<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#esx esx-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#aix aix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T06:38:03.667-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:9999" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0436"/>
        <description>Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:35.831-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:27.675-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:36.709-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9999 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:23.622-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:24:01.633-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.3.1-13.el4_8.1" test_ref="oval:org.mitre.oval:tst:39507"/>
            <criterion comment="kdebase-devel is earlier than 6:3.3.1-13.el4_8.1" test_ref="oval:org.mitre.oval:tst:40464"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.5.4-21.el5_5.1" test_ref="oval:org.mitre.oval:tst:40335"/>
            <criterion comment="kdebase-devel is earlier than 6:3.5.4-21.el5_5.1" test_ref="oval:org.mitre.oval:tst:40374"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9998" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4245"/>
        <description>Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:38.878-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:27.493-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:36.516-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9998 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:42.696-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:24:01.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.6-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:39912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9997" version="5" class="vulnerability">
      <metadata>
        <title>The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0718"/>
        <description>The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:21.181-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:27.199-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:36.215-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9997 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:50.342-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:24:00.946-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30799"/>
          <criterion comment="mozilla is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30278"/>
          <criterion comment="mozilla-chat is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30755"/>
          <criterion comment="mozilla-mail is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30570"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30230"/>
          <criterion comment="mozilla-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30288"/>
          <criterion comment="mozilla-nss is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30323"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30339"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30813"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30660"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9996" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2798"/>
        <description>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:10.334-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:26.770-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:35.766-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9996 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:02.908-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:24:00.367-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:33627"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34238"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34171"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:33767"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34147"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34640"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34202"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34749"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34767"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34660"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34728"/>
            <criterion comment="krb5 is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34350"/>
            <criterion comment="krb5-libs is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34575"/>
            <criterion comment="krb5-server is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34729"/>
            <criterion comment="krb5-devel is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34195"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9995" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys.  NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1056"/>
        <description>The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys.  NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:05.980-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:26.348-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:35.189-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9995 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:25.620-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:59.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32158"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32589"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32704"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32562"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32078"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32513"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32231"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32097"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32708"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9994" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2210"/>
        <description>Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:16.910-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:25.828-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:34.694-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9994 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:07.247-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:59.144-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38621"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38710"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38897"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38330"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38382"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38913"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38781"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38614"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38727"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38447"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38465"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38839"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38248"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38879"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38157"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38757"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9993" version="5" class="vulnerability">
      <metadata>
        <title>pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2672"/>
        <description>pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:27.771-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:25.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:34.487-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9993 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:10.379-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:58.813-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="lm_sensors-devel is earlier than 0:2.8.7-2.40.3" test_ref="oval:org.mitre.oval:tst:31850"/>
          <criterion comment="lm_sensors is earlier than 0:2.8.7-2.40.3" test_ref="oval:org.mitre.oval:tst:32360"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9992" version="5" class="vulnerability">
      <metadata>
        <title>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626"/>
        <description>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:48.624-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:25.147-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:33.964-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9992 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:00.441-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:58.162-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32437"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32206"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:31553"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32284"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.4" test_ref="oval:org.mitre.oval:tst:32545"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32254"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32499"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9991" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6102"/>
        <description>Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:44.536-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:24.308-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:33.178-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9991 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:27.363-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:57.195-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33279"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33033"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33135"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32975"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33134"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32756"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33026"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33238"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33343"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32868"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32574"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33217"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33260"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33106"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33262"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33329"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32993"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33159"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33053"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33163"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33308"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32484"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33294"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33176"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32802"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32909"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33270"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33234"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33180"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32796"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33158"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33322"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33297"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33211"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33206"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33346"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33222"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33340"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33228"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33187"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33289"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33242"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33068"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33283"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33337"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:32984"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33352"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33122"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9990" version="5" class="vulnerability">
      <metadata>
        <title>The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1630"/>
        <description>The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:18.827-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:23.779-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:32.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9990 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:26.346-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:56.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38892"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38222"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:37924"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38847"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38834"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38158"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38513"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38317"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38277"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38667"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38814"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:37971"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38820"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38641"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38838"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38699"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38813"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38840"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38890"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38529"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38350"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38066"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38388"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9989" version="5" class="vulnerability">
      <metadata>
        <title>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055"/>
        <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:59.777-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:23.584-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:32.436-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9989 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:28.764-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:56.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="libpcap is earlier than 14:0.7.2-7.E3.1" test_ref="oval:org.mitre.oval:tst:30562"/>
          <criterion comment="tcpdump is earlier than 14:3.7.2-7.E3.1" test_ref="oval:org.mitre.oval:tst:30488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9988" version="5" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6142"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:40.683-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:23.364-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:32.209-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9988 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:17.179-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:55.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.el3" test_ref="oval:org.mitre.oval:tst:32449"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.el4" test_ref="oval:org.mitre.oval:tst:33384"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9987" version="5" class="vulnerability">
      <metadata>
        <title>The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5081"/>
        <description>The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:07.476-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:23.001-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:31.832-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9987 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:11.415-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:55.086-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="avahi-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:37798"/>
          <criterion comment="avahi-qt3 is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:38120"/>
          <criterion comment="avahi-tools is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:37859"/>
          <criterion comment="avahi-glib is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:37982"/>
          <criterion comment="avahi-qt3-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:38067"/>
          <criterion comment="avahi-compat-howl-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:38123"/>
          <criterion comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:38074"/>
          <criterion comment="avahi is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:37900"/>
          <criterion comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:38051"/>
          <criterion comment="avahi-glib-devel is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:38229"/>
          <criterion comment="avahi-compat-howl is earlier than 0:0.6.16-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:38201"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9986" version="5" class="vulnerability">
      <metadata>
        <title>Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2177"/>
        <description>Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:35.807-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:22.617-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:31.507-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9986 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:18.285-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:54.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31395"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:30763"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31684"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31547"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31390"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31408"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:30993"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31414"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31691"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9985" version="5" class="vulnerability">
      <metadata>
        <title>RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2223" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2223"/>
        <description>RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:42.350-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:22.376-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:31.248-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9985 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:53.367-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:54.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="quagga is earlier than 0:0.96.2-11.3E" test_ref="oval:org.mitre.oval:tst:32541"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="quagga-devel is earlier than 0:0.98.3-2.4E" test_ref="oval:org.mitre.oval:tst:32744"/>
            <criterion comment="quagga is earlier than 0:0.98.3-2.4E" test_ref="oval:org.mitre.oval:tst:32471"/>
            <criterion comment="quagga-contrib is earlier than 0:0.98.3-2.4E" test_ref="oval:org.mitre.oval:tst:32544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9984" version="5" class="vulnerability">
      <metadata>
        <title>The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3108"/>
        <description>The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:59.428-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:21.994-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:30.859-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9984 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:57.379-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:53.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.24" test_ref="oval:org.mitre.oval:tst:35001"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.24" test_ref="oval:org.mitre.oval:tst:34962"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.24" test_ref="oval:org.mitre.oval:tst:34324"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35545"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35457"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35580"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.8b-8.3.el5_0.2" test_ref="oval:org.mitre.oval:tst:35181"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8b-8.3.el5_0.2" test_ref="oval:org.mitre.oval:tst:35460"/>
            <criterion comment="openssl is earlier than 0:0.9.8b-8.3.el5_0.2" test_ref="oval:org.mitre.oval:tst:35053"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9983" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3694"/>
        <description>Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:34.640-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:21.628-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:30.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9983 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:56.841-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:53.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32443"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32730"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32800"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32566"/>
            <criterion comment="ruby is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32264"/>
            <criterion comment="irb is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32482"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32617"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32600"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32723"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32881"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32751"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32913"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32117"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32804"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9982" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3292"/>
        <description>Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:28.890-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:20.856-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:29.709-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9982 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:49.081-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:52.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39717"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39629"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39915"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39741"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:40003"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39901"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39326"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39580"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:40010"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39927"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39619"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39111"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39417"/>
            <criterion comment="php is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39899"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39642"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39821"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39461"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39627"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39886"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39848"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39908"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39883"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39544"/>
            <criterion comment="php-common is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39804"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39875"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39748"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39802"/>
            <criterion comment="php is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39053"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39854"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39980"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39581"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39954"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39018"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39463"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39634"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39436"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39969"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39664"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39913"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39765"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9981" version="6" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0694"/>
        <description>Buffer overflow in LHA 1.14 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to "command line processing," a different vulnerability than CVE-2004-0771.  NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:20.278-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:20.668-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:29.511-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9981 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:14.740-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:51.808-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="lha is earlier than 0:1.14i-10.4" test_ref="oval:org.mitre.oval:tst:29793"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9980" version="5" class="vulnerability">
      <metadata>
        <title>The generic_file_splice_write function in fs/splice.c in the Linux kernel before 2.6.19 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by splicing into an inode in order to create an executable file in a setgid directory, a different vulnerability than CVE-2008-4210.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3833" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3833"/>
        <description>The generic_file_splice_write function in fs/splice.c in the Linux kernel before 2.6.19 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by splicing into an inode in order to create an executable file in a setgid directory, a different vulnerability than CVE-2008-4210.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:45.387-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:20.249-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:29.188-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9980 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:59.733-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:51.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37778"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37855"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37870"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37881"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37504"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37738"/>
          <criterion comment="kernel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37774"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37247"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37715"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37954"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37668"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37947"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:998" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Xorg Privilege Escalation via Pixmaps Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>X</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2495"/>
        <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-12T01:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 9 (x86,Xorg) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 118908-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1337"/>
            <criterion comment="File Xorg exists" negate="false" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86,Xorg) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 118966-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1335"/>
            <criterion comment="File Xorg exists" negate="false" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="The Xorg X server is running" negate="false" test_ref="oval:org.mitre.oval:tst:1334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9979" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4352"/>
        <description>Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:15.192-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:19.616-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:28.532-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9979 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:46.216-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:50.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 0:2.02-11.el3" test_ref="oval:org.mitre.oval:tst:35634"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:34998"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35446"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35156"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35404"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35455"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35415"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35178"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.1" test_ref="oval:org.mitre.oval:tst:35574"/>
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:34735"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35585"/>
            <criterion comment="xpdf is earlier than 1:3.00-14.el4" test_ref="oval:org.mitre.oval:tst:35315"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35591"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35283"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35537"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35498"/>
            <criterion comment="cups-lpd is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35274"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35509"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35147"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35549"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35527"/>
            <criterion comment="cups-libs is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35427"/>
            <criterion comment="tetex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35459"/>
            <criterion comment="cups-devel is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35508"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35407"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34618"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34727"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35496"/>
            <criterion comment="cups is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35530"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9978" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment.  NOTE: some original raw sources combined this issue with CVE-2006-1524, but they are different bugs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2071"/>
        <description>Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment.  NOTE: some original raw sources combined this issue with CVE-2006-1524, but they are different bugs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:57.150-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:19.204-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:28.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9978 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:27.461-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:50.053-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33074"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32633"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33103"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33001"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32937"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32280"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33127"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32855"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33021"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32678"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32900"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33014"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32947"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32944"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32956"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32602"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33081"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32892"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9977" version="5" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6283"/>
        <description>Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:27:39.267-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:18.885-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:27.771-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9977 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:55.612-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:49.653-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="bind-utils is earlier than 0:9.3.4-6.P1.el5" test_ref="oval:org.mitre.oval:tst:35853"/>
          <criterion comment="bind-libbind-devel is earlier than 0:9.3.4-6.P1.el5" test_ref="oval:org.mitre.oval:tst:36573"/>
          <criterion comment="bind-devel is earlier than 0:9.3.4-6.P1.el5" test_ref="oval:org.mitre.oval:tst:36695"/>
          <criterion comment="bind-chroot is earlier than 0:9.3.4-6.P1.el5" test_ref="oval:org.mitre.oval:tst:36618"/>
          <criterion comment="caching-nameserver is earlier than 0:9.3.4-6.P1.el5" test_ref="oval:org.mitre.oval:tst:36833"/>
          <criterion comment="bind-sdb is earlier than 0:9.3.4-6.P1.el5" test_ref="oval:org.mitre.oval:tst:36572"/>
          <criterion comment="bind is earlier than 0:9.3.4-6.P1.el5" test_ref="oval:org.mitre.oval:tst:36755"/>
          <criterion comment="bind-libs is earlier than 0:9.3.4-6.P1.el5" test_ref="oval:org.mitre.oval:tst:36364"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9976" version="5" class="vulnerability">
      <metadata>
        <title>Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1519"/>
        <description>Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:57.423-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:18.667-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:27.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9976 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:00.766-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:49.312-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.13" test_ref="oval:org.mitre.oval:tst:31246"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.9" test_ref="oval:org.mitre.oval:tst:31854"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9975" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2475" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2475"/>
        <description>Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:39.402-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:18.451-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:27.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9975 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:56.442-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:48.927-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="unzip is earlier than 0:5.50-35.EL3" test_ref="oval:org.mitre.oval:tst:30464"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="unzip is earlier than 0:5.51-9.EL4.5" test_ref="oval:org.mitre.oval:tst:33619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9974" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0840"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:36.838-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:18.223-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:27.066-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9974 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:58.946-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:48.590-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39831"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39445"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40225"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40023"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9973" version="5" class="vulnerability">
      <metadata>
        <title>src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2374"/>
        <description>src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:27:11.733-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:17.888-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:26.715-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9973 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:24.563-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:48.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bluez-libs is earlier than 0:2.10-3" test_ref="oval:org.mitre.oval:tst:37371"/>
            <criterion comment="bluez-utils-cups is earlier than 0:2.10-2.4" test_ref="oval:org.mitre.oval:tst:37307"/>
            <criterion comment="bluez-utils is earlier than 0:2.10-2.4" test_ref="oval:org.mitre.oval:tst:36921"/>
            <criterion comment="bluez-libs-devel is earlier than 0:2.10-3" test_ref="oval:org.mitre.oval:tst:37129"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bluez-libs is earlier than 0:3.7-1.1" test_ref="oval:org.mitre.oval:tst:37391"/>
            <criterion comment="bluez-utils-cups is earlier than 0:3.7-2.2" test_ref="oval:org.mitre.oval:tst:37349"/>
            <criterion comment="bluez-utils is earlier than 0:3.7-2.2" test_ref="oval:org.mitre.oval:tst:37379"/>
            <criterion comment="bluez-libs-devel is earlier than 0:3.7-1.1" test_ref="oval:org.mitre.oval:tst:36988"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9972" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a "Content-Disposition: attachment" and an invalid "Content-Type: plain/text," which prevents Firefox from rendering future plain text files within the browser.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0592"/>
        <description>Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a "Content-Disposition: attachment" and an invalid "Content-Type: plain/text," which prevents Firefox from rendering future plain text files within the browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:01.426-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:17.359-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:26.170-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9972 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:24.332-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:47.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36256"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36236"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35996"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36279"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36052"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36034"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35748"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35994"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36164"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36050"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el4" test_ref="oval:org.mitre.oval:tst:36202"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36193"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36093"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36053"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.10.el4" test_ref="oval:org.mitre.oval:tst:35919"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35600"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36141"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35397"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:36281"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:35480"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el5" test_ref="oval:org.mitre.oval:tst:35675"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9971" version="5" class="vulnerability">
      <metadata>
        <title>TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0183"/>
        <description>TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:17.472-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:17.165-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:25.906-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9971 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:52.319-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:46.985-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="libpcap is earlier than 14:0.7.2-7.E3.2" test_ref="oval:org.mitre.oval:tst:30722"/>
          <criterion comment="tcpdump is earlier than 14:3.7.2-7.E3.2" test_ref="oval:org.mitre.oval:tst:29722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9970" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1460" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1460"/>
        <description>Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:29.604-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:16.878-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:25.648-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9970 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:05.931-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:46.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:997" version="4" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise Linux 3 Kernel Serial Link Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0461"/>
        <description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.280-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:12.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:927 - Removed unneeded negate=&quot;false&quot; and added &quot;xsi:nil='true'&quot; to filenames to indicate directory is the file object, not the files in the directory." date="2012-04-04T14:37:00.449-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-04-04T14:40:09.247-04:00">INTERIM</status_change>
            <status_change date="2012-04-23T04:00:24.894-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kernel version is less than 2.4.21-15.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1342"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/proc/tty/driver/serial is world-readable" negate="false" test_ref="oval:org.mitre.oval:tst:1341"/>
          <criterion comment="/proc/tty/driver/ is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:1340"/>
          <criterion comment="/proc/tty/ is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:1339"/>
          <criterion comment="/proc/ is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:1338"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9969" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0882"/>
        <description>Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:23.576-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:16.660-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:25.410-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9969 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:50.318-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:46.319-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="samba-common is earlier than 0:3.0.7-1.3E.1" test_ref="oval:org.mitre.oval:tst:30820"/>
          <criterion comment="samba-swat is earlier than 0:3.0.7-1.3E.1" test_ref="oval:org.mitre.oval:tst:31128"/>
          <criterion comment="samba-client is earlier than 0:3.0.7-1.3E.1" test_ref="oval:org.mitre.oval:tst:31144"/>
          <criterion comment="samba is earlier than 0:3.0.7-1.3E.1" test_ref="oval:org.mitre.oval:tst:31136"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9968" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.  NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0577" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0577"/>
        <description>Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.  NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:23.235-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:16.457-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:25.062-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9968 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:12.213-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:45.983-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.56" test_ref="oval:org.mitre.oval:tst:37836"/>
          <criterion comment="cups is earlier than 1:1.1.17-13.3.56" test_ref="oval:org.mitre.oval:tst:38122"/>
          <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.56" test_ref="oval:org.mitre.oval:tst:38220"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9967" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2834"/>
        <description>Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:04.925-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:14.306-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:22.938-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9967 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:08.581-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:43.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-40.2.0.EL3" test_ref="oval:org.mitre.oval:tst:34967"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-40.2.0.EL3" test_ref="oval:org.mitre.oval:tst:34907"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-40.2.0.EL3" test_ref="oval:org.mitre.oval:tst:34663"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34624"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34985"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34600"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35058"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34840"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34776"/>
            <criterion comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34590"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35090"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35105"/>
            <criterion comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34685"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34233"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34999"/>
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34898"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35138"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34744"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34838"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34903"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34783"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35127"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35036"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35135"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35130"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34854"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34867"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35190"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34239"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34269"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35163"/>
            <criterion comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34429"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34318"/>
            <criterion comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34522"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34715"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34987"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35152"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34733"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34947"/>
            <criterion comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34830"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35107"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34895"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34353"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35096"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34629"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35089"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34887"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34939"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34988"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34591"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34737"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34412"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34871"/>
            <criterion comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34717"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34942"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35019"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34969"/>
            <criterion comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35129"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34980"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34548"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35098"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34983"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34904"/>
            <criterion comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35206"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34571"/>
            <criterion comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35205"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35157"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35006"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34919"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35196"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35104"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34449"/>
            <criterion comment="openoffice.org is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34768"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35222"/>
            <criterion comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35111"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35231"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35237"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34488"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34457"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35232"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35235"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35194"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34862"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34938"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34706"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34766"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35172"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34709"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35079"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35080"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34726"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34972"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35101"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34674"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35094"/>
            <criterion comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35137"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34909"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35201"/>
            <criterion comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34989"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35225"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34978"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35038"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35198"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34866"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34918"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34874"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35203"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35211"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34963"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34932"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35151"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34242"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35217"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35027"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34687"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34666"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34639"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34834"/>
            <criterion comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35238"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35072"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35082"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34878"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34330"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35063"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34592"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35109"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34705"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34515"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34792"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35068"/>
            <criterion comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35132"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35188"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35128"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34875"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34788"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35158"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34970"/>
            <criterion comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34996"/>
            <criterion comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34349"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35193"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9966" version="5" class="vulnerability">
      <metadata>
        <title>HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2786"/>
        <description>HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:22.234-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:13.731-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:22.390-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9966 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:04.477-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:42.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9965" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0415"/>
        <description>Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:55.371-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:13.448-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:22.093-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9965 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:36.637-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:42.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30827"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30622"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30627"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30676"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30823"/>
          <criterion comment="kernel is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30750"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30596"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30833"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30830"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9964" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3389"/>
        <description>Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:24.387-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:13.136-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:21.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9964 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:32.583-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:41.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34755"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34881"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34336"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34784"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9963" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4986"/>
        <description>Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:14.834-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:12.686-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:21.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9963 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:13.686-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:41.345-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36023"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36184"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36260"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36208"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36311"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36459"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36349"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35927"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36419"/>
            <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36360"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36388"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35921"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36133"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9962" version="5" class="vulnerability">
      <metadata>
        <title>scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0225"/>
        <description>scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:20.355-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:12.374-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:20.913-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9962 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:20.268-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:40.838-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32634"/>
            <criterion comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32130"/>
            <criterion comment="openssh-server is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32453"/>
            <criterion comment="openssh-clients is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32516"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32587"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32475"/>
            <criterion comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32414"/>
            <criterion comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32296"/>
            <criterion comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32306"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9961" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1157" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1157"/>
        <description>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:17.084-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:11.827-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:20.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9961 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:17.007-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:40.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31478"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31488"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31751"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31647"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30850"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31749"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31658"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31636"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31780"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30828"/>
            <criterion comment="firefox is earlier than 0:1.0.3-1.4.1" test_ref="oval:org.mitre.oval:tst:31646"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31716"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31758"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9960" version="5" class="vulnerability">
      <metadata>
        <title>The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2453" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2453"/>
        <description>The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:35.164-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:11.512-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:19.974-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9960 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:47:07.913-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:39.725-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34290"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34311"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34023"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34185"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34210"/>
          <criterion comment="kernel is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34306"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34033"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34168"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34261"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34155"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.6.el5" test_ref="oval:org.mitre.oval:tst:34278"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9959" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the "beg + rlen" issue.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2726"/>
        <description>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the "beg + rlen" issue.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:26:56.212-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:10.933-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:19.416-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9959 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:24.426-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:38.991-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9958" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412"/>
        <description>Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:27.599-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:10.553-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.965-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9958 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:46.310-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:38.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39033"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:38392"/>
            <criterion comment="httpd is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39071"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="apr-devel is earlier than 0:0.9.4-24.9.el4_8.2" test_ref="oval:org.mitre.oval:tst:38759"/>
            <criterion comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.2" test_ref="oval:org.mitre.oval:tst:39047"/>
            <criterion comment="apr is earlier than 0:0.9.4-24.9.el4_8.2" test_ref="oval:org.mitre.oval:tst:39098"/>
            <criterion comment="apr-util is earlier than 0:0.9.4-22.el4_8.2" test_ref="oval:org.mitre.oval:tst:38182"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:38932"/>
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:39149"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38625"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38971"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:39108"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38986"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9957" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1188"/>
        <description>Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:10.245-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:10.238-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.645-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9957 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:15.930-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:37.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39438"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_8.5" test_ref="oval:org.mitre.oval:tst:39221"/>
            <criterion comment="xpdf is earlier than 1:3.00-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:38963"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39062"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39529"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9956" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1098"/>
        <description>Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:26:38.745-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:09.879-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.380-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9956 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:04.827-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:37.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:38276"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:37661"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:37652"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:37769"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:38561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9955" version="5" class="vulnerability">
      <metadata>
        <title>ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connectivity loss) by opening a large number of UNIX sockets without closing them, which triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0798"/>
        <description>ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connectivity loss) by opening a large number of UNIX sockets without closing them, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:07.606-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:09.628-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.107-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9955 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:45.300-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:37.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="acpid is earlier than 0:1.0.2-4" test_ref="oval:org.mitre.oval:tst:38604"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="acpid is earlier than 0:1.0.3-2.el4_7.1" test_ref="oval:org.mitre.oval:tst:38456"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="acpid is earlier than 0:1.0.4-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:38613"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9954" version="8" class="vulnerability">
      <metadata>
        <title>Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2800"/>
        <description>Memory leak in the seq_file implemenetation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:02.009-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:09.374-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:17.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9954 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:17.989-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:36.704-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9954 - Fixed typo in title and description of def:9954" date="2014-05-22T10:52:00.994-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T10:54:21.347-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:50.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9953" version="5" class="vulnerability">
      <metadata>
        <title>The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3740"/>
        <description>The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:36.571-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:08.852-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:17.310-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9953 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:12.405-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:36.089-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34804"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34557"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34837"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34795"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34562"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34357"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34379"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34873"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34870"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34374"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9952" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0990"/>
        <description>Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:40.553-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:08.647-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:17.085-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9952 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:20.355-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:35.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gd is earlier than 0:1.8.4-12.3.1" test_ref="oval:org.mitre.oval:tst:31045"/>
          <criterion comment="gd-devel is earlier than 0:1.8.4-12.3.1" test_ref="oval:org.mitre.oval:tst:31109"/>
          <criterion comment="gd-progs is earlier than 0:1.8.4-12.3.1" test_ref="oval:org.mitre.oval:tst:31083"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9951" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6107"/>
        <description>Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:26:02.643-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:08.408-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:16.794-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9951 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:41.195-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:35.425-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="dbus-glib is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:32768"/>
          <criterion comment="dbus-devel is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:33345"/>
          <criterion comment="dbus-x11 is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:33280"/>
          <criterion comment="dbus-python is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:32745"/>
          <criterion comment="dbus is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:33276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9950" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3837"/>
        <description>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:29.260-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:07.762-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:16.188-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9950 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:48.603-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:34.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9949" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demonstrated using an HFS filesystem image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6056"/>
        <description>Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demonstrated using an HFS filesystem image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:45.646-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:07.485-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:15.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9949 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:24.311-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:34.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9948" version="5" class="vulnerability">
      <metadata>
        <title>The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0075"/>
        <description>The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:06.895-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:07.206-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:15.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9948 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:28.440-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:33.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
          <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9947" version="5" class="vulnerability">
      <metadata>
        <title>PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2314" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2314"/>
        <description>PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:08.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:06.674-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:14.907-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9947 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:36.218-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:33.201-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32465"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32618"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32497"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32527"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32392"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32719"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32621"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32195"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32628"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32601"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:31936"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32101"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31976"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32564"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32038"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32648"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31768"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32626"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31950"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32604"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32472"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32278"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9946" version="5" class="vulnerability">
      <metadata>
        <title>The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1918" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1918"/>
        <description>The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:37.137-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:06.478-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:14.706-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9946 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:50.109-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:32.875-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="tar is earlier than 0:1.13.25-14.RHEL3" test_ref="oval:org.mitre.oval:tst:31888"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9945" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3829"/>
        <description>Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:03.438-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:06.192-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:14.403-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9945 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:19.338-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:32.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9944" version="5" class="vulnerability">
      <metadata>
        <title>smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906"/>
        <description>smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:02.322-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:05.773-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:13.964-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9944 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:33.158-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:31.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39355"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39369"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39545"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39162"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39589"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39603"/>
            <criterion comment="samba is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39658"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39633"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39222"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39493"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39205"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9943" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0914" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0914"/>
        <description>Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:21.628-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:05.198-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:13.375-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9943 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:38.482-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:30.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30653"/>
          <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30795"/>
          <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:31038"/>
          <criterion comment="XFree86-libs is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30973"/>
          <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30713"/>
          <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30995"/>
          <criterion comment="XFree86-twm is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:31069"/>
          <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30155"/>
          <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:31142"/>
          <criterion comment="XFree86-doc is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:31107"/>
          <criterion comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.4" test_ref="oval:org.mitre.oval:tst:30867"/>
          <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30816"/>
          <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30980"/>
          <criterion comment="openmotif is earlier than 0:2.2.3-4.RHEL3.4" test_ref="oval:org.mitre.oval:tst:31105"/>
          <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30942"/>
          <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30994"/>
          <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30972"/>
          <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30197"/>
          <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30720"/>
          <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30777"/>
          <criterion comment="XFree86-xdm is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30811"/>
          <criterion comment="XFree86-sdk is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30529"/>
          <criterion comment="XFree86 is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:31025"/>
          <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30781"/>
          <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30607"/>
          <criterion comment="XFree86-xfs is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30885"/>
          <criterion comment="XFree86-tools is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30637"/>
          <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:31060"/>
          <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30699"/>
          <criterion comment="openmotif-devel is earlier than 0:2.2.3-4.RHEL3.4" test_ref="oval:org.mitre.oval:tst:30744"/>
          <criterion comment="XFree86-xauth is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30991"/>
          <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30327"/>
          <criterion comment="XFree86-devel is earlier than 0:4.3.0-78.EL" test_ref="oval:org.mitre.oval:tst:30499"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9942" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0397" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0397"/>
        <description>Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:11.244-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:04.911-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:13.114-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9942 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:43.952-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:30.567-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gstreamer-plugins-devel is earlier than 0:0.8.5-1.EL.2" test_ref="oval:org.mitre.oval:tst:38235"/>
            <criterion comment="gstreamer-plugins is earlier than 0:0.8.5-1.EL.2" test_ref="oval:org.mitre.oval:tst:37467"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38180"/>
            <criterion comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38318"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9941" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147"/>
        <description>Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:46.519-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:04.319-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:12.464-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9941 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:17.397-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:29.292-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9940" version="5" class="vulnerability">
      <metadata>
        <title>CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2154"/>
        <description>CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:31.002-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:04.112-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:12.245-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9940 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:35.341-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:28.966-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.29" test_ref="oval:org.mitre.oval:tst:31955"/>
          <criterion comment="cups is earlier than 1:1.1.17-13.3.29" test_ref="oval:org.mitre.oval:tst:31393"/>
          <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.29" test_ref="oval:org.mitre.oval:tst:31828"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:994" version="1" class="vulnerability">
      <metadata>
        <title>CVS error_prog_name Double-free Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0416"/>
        <description>Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Red Hat Enterprise 3 is installed" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="cvs rpm version prior to 1.11.2-24 is installed" test_ref="oval:org.mitre.oval:tst:1347"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9939" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3863"/>
        <description>Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:58.147-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:03.812-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.909-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9939 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:05.798-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:28.537-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-24.7" test_ref="oval:org.mitre.oval:tst:37704"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-33.el4_7.1" test_ref="oval:org.mitre.oval:tst:37804"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.4-4.1.1.el5_2" test_ref="oval:org.mitre.oval:tst:38101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9938" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0452" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0452"/>
        <description>Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:14.746-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:03.537-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.615-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9938 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:04.938-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:28.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 2:5.8.0-89.10" test_ref="oval:org.mitre.oval:tst:31361"/>
            <criterion comment="perl is earlier than 2:5.8.0-89.10" test_ref="oval:org.mitre.oval:tst:30931"/>
            <criterion comment="perl-CPAN is earlier than 2:1.61-89.10" test_ref="oval:org.mitre.oval:tst:30901"/>
            <criterion comment="perl-CGI is earlier than 2:2.81-89.10" test_ref="oval:org.mitre.oval:tst:31227"/>
            <criterion comment="perl-DB_File is earlier than 2:1.804-89.10" test_ref="oval:org.mitre.oval:tst:30945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 3:5.8.5-12.1.1" test_ref="oval:org.mitre.oval:tst:31049"/>
            <criterion comment="perl is earlier than 3:5.8.5-12.1" test_ref="oval:org.mitre.oval:tst:31120"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9937" version="5" class="vulnerability">
      <metadata>
        <title>verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4790"/>
        <description>verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:04.969-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:03.306-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.404-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9937 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:46.269-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:27.748-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gnutls is earlier than 0:1.0.20-3.2.3" test_ref="oval:org.mitre.oval:tst:32934"/>
          <criterion comment="gnutls-devel is earlier than 0:1.0.20-3.2.3" test_ref="oval:org.mitre.oval:tst:32930"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9936" version="5" class="vulnerability">
      <metadata>
        <title>The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3107"/>
        <description>The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:38.481-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:02.973-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.087-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9936 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:42.855-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:27.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34750"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34474"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34411"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34408"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34451"/>
          <criterion comment="kernel is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34756"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34502"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34532"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34633"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34714"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.8.el5" test_ref="oval:org.mitre.oval:tst:34272"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9935" version="5" class="vulnerability">
      <metadata>
        <title>The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0408"/>
        <description>The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:21.005-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:02.754-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:10.820-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9935 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:54.796-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:26.979-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-31.el5_4.4" test_ref="oval:org.mitre.oval:tst:40344"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-31.el5_4.4" test_ref="oval:org.mitre.oval:tst:39553"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-31.el5_4.4" test_ref="oval:org.mitre.oval:tst:40118"/>
          <criterion comment="httpd is earlier than 0:2.2.3-31.el5_4.4" test_ref="oval:org.mitre.oval:tst:40311"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9934" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3811"/>
        <description>Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:21.415-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:02.264-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:10.308-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9934 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:10.292-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:26.360-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9933" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0304"/>
        <description>Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:24.618-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:01.902-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:09.964-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9933 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:11.168-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:25.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9932" version="5" class="vulnerability">
      <metadata>
        <title>The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0555"/>
        <description>The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:06.862-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:01.619-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:09.674-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9932 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:41.945-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:25.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9931" version="5" class="vulnerability">
      <metadata>
        <title>The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0633" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0633"/>
        <description>The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:35.841-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:01.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:09.463-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9931 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:06.479-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:25.177-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ethereal-gnome is earlier than 0:0.10.5-0.30E.2" test_ref="oval:org.mitre.oval:tst:29799"/>
          <criterion comment="ethereal is earlier than 0:0.10.5-0.30E.2" test_ref="oval:org.mitre.oval:tst:30522"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9930" version="5" class="vulnerability">
      <metadata>
        <title>The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2583" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2583"/>
        <description>The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:12.276-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:01.198-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:09.223-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9930 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:28.902-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:24.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36197"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36749"/>
          <criterion comment="mysql-test is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36750"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36831"/>
          <criterion comment="mysql-server is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36646"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:993" version="1" class="vulnerability">
      <metadata>
        <title>CVS Improper Handling of Malformed Entry Lines</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0414"/>
        <description>CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1347"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9929" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1526"/>
        <description>Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&amp;" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:13.621-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:00.756-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:08.776-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9929 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:16.983-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:24.304-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:31792"/>
          <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32571"/>
          <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32223"/>
          <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32554"/>
          <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32521"/>
          <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32568"/>
          <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32369"/>
          <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:31728"/>
          <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32424"/>
          <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32510"/>
          <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32532"/>
          <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32174"/>
          <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32670"/>
          <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32705"/>
          <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32274"/>
          <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32683"/>
          <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32330"/>
          <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9928" version="3" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in.  NOTE: this issue might be subsumed by CVE-2008-0655.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5663"/>
        <description>Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in.  NOTE: this issue might be subsumed by CVE-2008-0655.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:19.094-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:00.477-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:08.486-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:8.1.2-1.el3.6" test_ref="oval:org.mitre.oval:tst:36324"/>
            <criterion comment="acroread is earlier than 0:8.1.2-1.el3.6" test_ref="oval:org.mitre.oval:tst:36153"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:8.1.2-1.el4.2" test_ref="oval:org.mitre.oval:tst:36156"/>
            <criterion comment="acroread is earlier than 0:8.1.2-1.el4.2" test_ref="oval:org.mitre.oval:tst:36293"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:8.1.2-1.el5.3" test_ref="oval:org.mitre.oval:tst:35792"/>
            <criterion comment="acroread is earlier than 0:8.1.2-1.el5.3" test_ref="oval:org.mitre.oval:tst:35912"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9927" version="5" class="vulnerability">
      <metadata>
        <title>Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1856" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1856"/>
        <description>Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:25.870-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:00.202-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:08.196-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9927 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:09.055-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:23.842-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9926" version="5" class="vulnerability">
      <metadata>
        <title>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180"/>
        <description>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:48.604-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:59.474-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:07.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9926 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:18.008-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:22.733-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9925" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0005"/>
        <description>Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:56.373-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:59.151-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:07.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9925 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:39.777-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:22.259-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30471"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30355"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30877"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30918"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:30872"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31137"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31139"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31140"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9924" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0585"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:26.737-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:58.772-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:06.821-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9924 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:21.439-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:21.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9923" version="5" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0372"/>
        <description>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:07.106-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:58.549-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:06.592-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9923 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:35.821-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:21.321-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gftp is earlier than 1:2.0.14-4" test_ref="oval:org.mitre.oval:tst:31807"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gftp is earlier than 1:2.0.17-5" test_ref="oval:org.mitre.oval:tst:31775"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9922" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0356"/>
        <description>Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:19.288-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:58.214-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:06.246-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9922 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:42.919-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:20.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9921" version="5" class="vulnerability">
      <metadata>
        <title>net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3621"/>
        <description>net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:02.374-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:57.700-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:05.730-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9921 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:10.871-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:20.154-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39504"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39362"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39704"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39759"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39722"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39734"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39394"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39578"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39019"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39604"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39609"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39674"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39635"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39630"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39766"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39742"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39295"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:38900"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39772"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39784"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39625"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39731"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9920" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3934" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3934"/>
        <description>Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:56.398-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:57.409-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:05.422-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9920 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:04.112-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:19.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:992" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX Running on Itanium Platforms Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3295" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3295"/>
        <description>Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-31T12:19:00.000-04:00" comment="Updated reference to CVE-2005-3295.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:54.943-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.727-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.989-04:00">ACCEPTED</status_change>
            <modified comment="Updated for CVE-2005-3295" date="2008-09-09T10:39:00.374-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-09-09T10:42:43.389-04:00">INTERIM</status_change>
            <status_change date="2008-09-29T04:00:53.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:44.207-05:00">INTERIM</status_change>
            <status_change date="2014-03-10T04:00:52.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX01233">
        <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:1350"/>
        <criteria negate="true" operator="OR" comment="Patch PHKL_33713 and PHKL_33714 are installed">
          <criterion comment="Patch PHKL_33713 is installed" test_ref="oval:org.mitre.oval:tst:1349"/>
          <criterion comment="Patch PHKL_33714 is installed" test_ref="oval:org.mitre.oval:tst:1348"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9919" version="5" class="vulnerability">
      <metadata>
        <title>The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11.  NOTE: this is a regression error related to CVE-2003-0967.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3111"/>
        <description>The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11.  NOTE: this is a regression error related to CVE-2003-0967.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:26.493-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:57.192-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:05.192-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9919 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:16.490-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:19.277-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="freeradius-mysql is earlier than 0:1.1.3-1.5.el5_4" test_ref="oval:org.mitre.oval:tst:39467"/>
          <criterion comment="freeradius-unixODBC is earlier than 0:1.1.3-1.5.el5_4" test_ref="oval:org.mitre.oval:tst:38652"/>
          <criterion comment="freeradius is earlier than 0:1.1.3-1.5.el5_4" test_ref="oval:org.mitre.oval:tst:39117"/>
          <criterion comment="freeradius-postgresql is earlier than 0:1.1.3-1.5.el5_4" test_ref="oval:org.mitre.oval:tst:39124"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9918" version="5" class="vulnerability">
      <metadata>
        <title>The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1516"/>
        <description>The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:00.621-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:56.902-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:04.911-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9918 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:15.812-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:18.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32252"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32551"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32245"/>
          <criterion comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32560"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9917" version="5" class="vulnerability">
      <metadata>
        <title>The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1071"/>
        <description>The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:56.632-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:56.627-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:04.460-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9917 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:08.981-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:18.540-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30934"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30708"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30577"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30874"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30794"/>
          <criterion comment="kernel is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30892"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30873"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:31080"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30866"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9916" version="5" class="vulnerability">
      <metadata>
        <title>The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1641" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1641"/>
        <description>The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:59.000-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:56.309-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:04.135-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9916 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:29.646-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:18.121-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40501"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40283"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40807"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40842"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40793"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40732"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40830"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40349"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39978"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39896"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40791"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40580"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9915" version="5" class="vulnerability">
      <metadata>
        <title>MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function.  NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0903"/>
        <description>MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function.  NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:59.900-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:55.967-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:03.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9915 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:41.759-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:17.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32252"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32551"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32245"/>
            <criterion comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32560"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36197"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36749"/>
            <criterion comment="mysql-test is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36750"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36831"/>
            <criterion comment="mysql-server is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9914" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1190"/>
        <description>Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:45.873-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:55.358-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:03.175-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36548"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36455"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36422"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36295"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36406"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36334"/>
            <criterion comment="java-1.5.0-ibm is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36155"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36267"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35708"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35618"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36613"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36614"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36509"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36558"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36485"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35872"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36582"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36555"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36414"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36622"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36688"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36265"/>
            <criterion comment="java-1.6.0-ibm is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36319"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36706"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36205"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36535"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36515"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36523"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36323"/>
            <criterion comment="java-1.5.0-ibm is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35890"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35698"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35719"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36340"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36068"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36568"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9913" version="5" class="vulnerability">
      <metadata>
        <title>(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3919" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3919"/>
        <description>(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:34.598-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:55.138-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.897-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9913 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:08.214-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:17.306-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="xen-libs is earlier than 0:3.0.3-41.el5_1.5" test_ref="oval:org.mitre.oval:tst:36530"/>
          <criterion comment="xen is earlier than 0:3.0.3-41.el5_1.5" test_ref="oval:org.mitre.oval:tst:36543"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-41.el5_1.5" test_ref="oval:org.mitre.oval:tst:35758"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9912" version="5" class="vulnerability">
      <metadata>
        <title>Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2941"/>
        <description>Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:01.286-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:54.841-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9912 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:57.499-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:16.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5.1-25.rhel3.7" test_ref="oval:org.mitre.oval:tst:32470"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5.1-34.rhel4.5" test_ref="oval:org.mitre.oval:tst:32787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9911" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3985"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:30.778-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:54.584-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.400-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9911 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:47.631-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:16.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.16-4.el4" test_ref="oval:org.mitre.oval:tst:39002"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39838"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39032"/>
            <criterion comment="firefox is earlier than 0:3.0.16-1.el5_4" test_ref="oval:org.mitre.oval:tst:39721"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9910" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3461"/>
        <description>Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:11.203-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:54.313-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.117-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9910 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:24.863-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:16.079-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:32819"/>
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32069"/>
            <criterion comment="kdegraphics is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:33012"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32843"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32922"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:991" version="4" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in MIT Kerberos 5</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>MIT Kerberos 5 (krb5)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0523"/>
        <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:53.979-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:12.209-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:991 - Typo Corrections" date="2014-05-22T11:01:00.943-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:03:38.761-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:50.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="Red Hat Enterprise 3 is installed" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="krb5-libs rpm version prior to 1.2.7-24 is installed" test_ref="oval:org.mitre.oval:tst:1351"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9909" version="5" class="vulnerability">
      <metadata>
        <title>The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0456"/>
        <description>The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:17.573-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:53.991-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:01.775-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9909 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:27.127-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:15.646-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9908" version="5" class="vulnerability">
      <metadata>
        <title>Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5023"/>
        <description>Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:26.352-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:53.413-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:01.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9908 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:04.221-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:14.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9907" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0886"/>
        <description>Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:45.995-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:53.120-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:00.831-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9907 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:09.711-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:14.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="tetex-latex is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31559"/>
          <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.7" test_ref="oval:org.mitre.oval:tst:30890"/>
          <criterion comment="libtiff is earlier than 0:3.5.7-20.1" test_ref="oval:org.mitre.oval:tst:31042"/>
          <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31693"/>
          <criterion comment="kdegraphics is earlier than 7:3.1.3-3.7" test_ref="oval:org.mitre.oval:tst:31096"/>
          <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31615"/>
          <criterion comment="tetex is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31603"/>
          <criterion comment="libtiff-devel is earlier than 0:3.5.7-20.1" test_ref="oval:org.mitre.oval:tst:31022"/>
          <criterion comment="tetex-afm is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31685"/>
          <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31747"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9906" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0007"/>
        <description>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:14.903-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:52.896-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:00.639-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9906 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:44.361-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:14.171-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="gaim is earlier than 1:0.75-3.2.0" test_ref="oval:org.mitre.oval:tst:30440"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9905" version="5" class="vulnerability">
      <metadata>
        <title>QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1945" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1945"/>
        <description>QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:51.925-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:52.692-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:00.422-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9905 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:34.272-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:13.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="xen-libs is earlier than 0:3.0.3-64.el5_2.3" test_ref="oval:org.mitre.oval:tst:37651"/>
          <criterion comment="xen is earlier than 0:3.0.3-64.el5_2.3" test_ref="oval:org.mitre.oval:tst:37731"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-64.el5_2.3" test_ref="oval:org.mitre.oval:tst:37638"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9904" version="5" class="vulnerability">
      <metadata>
        <title>Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3377"/>
        <description>Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:26.189-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:52.436-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:00.153-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9904 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:51.281-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:13.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="perl-Net-DNS is earlier than 0:0.31-4.el3" test_ref="oval:org.mitre.oval:tst:34732"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="perl-Net-DNS is earlier than 0:0.48-2.el4" test_ref="oval:org.mitre.oval:tst:34581"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="perl-Net-DNS is earlier than 0:0.59-3.el5" test_ref="oval:org.mitre.oval:tst:34803"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9903" version="5" class="vulnerability">
      <metadata>
        <title>The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by triggering a free of non-allocated memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3806"/>
        <description>The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by triggering a free of non-allocated memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:54.626-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:51.984-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:59.686-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9903 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:37.341-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:12.754-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9902" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1175"/>
        <description>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:54.396-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:51.653-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:59.362-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9902 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:35.444-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:12.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31712"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31065"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31933"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31927"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31772"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31800"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31846"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31172"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31706"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9901" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in CIFS VFS in Linux kernel 2.6.23 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SMB responses that trigger the overflows in the SendReceive function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5904"/>
        <description>Multiple buffer overflows in CIFS VFS in Linux kernel 2.6.23 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SMB responses that trigger the overflows in the SendReceive function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:15.902-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:51.155-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:58.817-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9901 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:50.219-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:11.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36188"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36478"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36125"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36428"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:35983"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36049"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36310"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36246"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36377"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:35967"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36113"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36030"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35766"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36138"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36062"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35611"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35990"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35969"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36085"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36026"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36084"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36097"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36035"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35648"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9900" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2785" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2785"/>
        <description>Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:45.937-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:50.451-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:58.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9900 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:49.325-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:10.449-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37358"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37417"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37346"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:36845"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37059"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37083"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:36603"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37075"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37472"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.1.el4" test_ref="oval:org.mitre.oval:tst:36782"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37402"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37430"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37439"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37337"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:36865"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.1.el4" test_ref="oval:org.mitre.oval:tst:36898"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.21.el4" test_ref="oval:org.mitre.oval:tst:36910"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37455"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:36525"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37362"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:36596"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37517"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:37176"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37474"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37409"/>
            <criterion comment="devhelp is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:37522"/>
            <criterion comment="yelp is earlier than 0:2.16.0-20.el5" test_ref="oval:org.mitre.oval:tst:37008"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37414"/>
            <criterion comment="firefox is earlier than 0:3.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37297"/>
            <criterion comment="nspluginwrapper is earlier than 0:0.9.91.5-22.el5" test_ref="oval:org.mitre.oval:tst:37422"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9899" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0848"/>
        <description>Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:14.325-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:50.210-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:57.864-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9899 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:18.493-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:10.101-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39831"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39445"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40225"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40023"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9898" version="3" class="vulnerability">
      <metadata>
        <title>The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5689"/>
        <description>The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:39.463-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:49.838-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:57.522-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35191"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35272"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35384"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35413"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:34849"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35057"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35437"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:34760"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35256"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35392"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35317"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:34772"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9897" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0415"/>
        <description>Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:31.823-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:49.161-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:56.950-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9897 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:06.410-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:09.330-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36256"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36236"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35996"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36279"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36052"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36034"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35748"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35994"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36164"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36050"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el4" test_ref="oval:org.mitre.oval:tst:36202"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36193"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36093"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36053"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.10.el4" test_ref="oval:org.mitre.oval:tst:35919"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35600"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36141"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35397"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:36281"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:35480"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el5" test_ref="oval:org.mitre.oval:tst:35675"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9896" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0845"/>
        <description>Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:49.459-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:48.867-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:56.705-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9896 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:48.873-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:08.918-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39831"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39445"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40225"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40023"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9895" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3743"/>
        <description>Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:04.556-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:48.550-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:56.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9895 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:25.810-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:08.472-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32037"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32699"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32588"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32852"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32735"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32383"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32971"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32748"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32946"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32537"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9894" version="5" class="vulnerability">
      <metadata>
        <title>OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0386" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0386"/>
        <description>OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:11.376-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:48.314-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:56.140-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9894 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:41.374-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:08.150-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="openssh is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32634"/>
          <criterion comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32130"/>
          <criterion comment="openssh-server is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32453"/>
          <criterion comment="openssh-clients is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32516"/>
          <criterion comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9893" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2024"/>
        <description>Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:49.067-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:48.008-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:55.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9893 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:33.443-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:07.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32689"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32435"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32329"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9892" version="5" class="vulnerability">
      <metadata>
        <title>The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege Level (CPL) before accessing a debug register, which allows guest OS users to cause a denial of service (trap) on the host OS via a crafted application.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3722"/>
        <description>The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege Level (CPL) before accessing a debug register, which allows guest OS users to cause a denial of service (trap) on the host OS via a crafted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:35.775-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:47.788-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:55.600-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9892 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:07.868-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:07.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kmod-kvm is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:40222"/>
          <criterion comment="kvm-qemu-img is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:40287"/>
          <criterion comment="kvm-tools is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:39931"/>
          <criterion comment="kvm is earlier than 0:83-105.el5_4.27" test_ref="oval:org.mitre.oval:tst:39956"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9891" version="5" class="vulnerability">
      <metadata>
        <title>The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3620" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3620"/>
        <description>The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:39.465-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:47.311-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:55.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9891 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:28.143-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:06.718-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39504"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39362"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39704"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39759"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39722"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39734"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39394"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39578"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39019"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39604"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39609"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39674"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39635"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39630"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39766"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39742"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39295"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:38900"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39772"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39784"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39625"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39731"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9890" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0179"/>
        <description>Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:15.752-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:46.859-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:54.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9890 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:56.000-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:06.185-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9889" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1238"/>
        <description>Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:02.547-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:46.338-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9889 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:07.827-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:05.410-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9888" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4226"/>
        <description>Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:57.587-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.969-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.605-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9888 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:16.855-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:04.825-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:37860"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:37771"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:38036"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:37841"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:37839"/>
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:37940"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:38044"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:37640"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:37694"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9887" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2264" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2264"/>
        <description>Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:35.727-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.787-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.405-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9887 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:05.361-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:04.530-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9886" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the gst_qtp_trak_handler function in gst/qtdemux/qtdemux.c in GStreamer Plug-ins (aka gstreamer-plugins) 0.6.0 allows remote attackers to have an unknown impact via a crafted QuickTime media file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0398"/>
        <description>Array index error in the gst_qtp_trak_handler function in gst/qtdemux/qtdemux.c in GStreamer Plug-ins (aka gstreamer-plugins) 0.6.0 allows remote attackers to have an unknown impact via a crafted QuickTime media file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:18.984-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.596-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.189-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9886 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:11.841-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:04.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gstreamer-plugins-devel is earlier than 0:0.6.0-19" test_ref="oval:org.mitre.oval:tst:38088"/>
          <criterion comment="gstreamer-plugins is earlier than 0:0.6.0-19" test_ref="oval:org.mitre.oval:tst:38287"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9885" version="5" class="vulnerability">
      <metadata>
        <title>The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a bad address," which triggers a fault that prevents the unused memory from being cleared in the kernel buffer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5174"/>
        <description>The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a bad address," which triggers a fault that prevents the unused memory from being cleared in the kernel buffer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:06.557-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.177-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:52.707-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9885 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:10.946-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:03.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33074"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32633"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33103"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33001"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32937"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32280"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33127"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32855"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33021"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9884" version="5" class="vulnerability">
      <metadata>
        <title>browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0780"/>
        <description>browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:19.280-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:44.545-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:52.104-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9884 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:32.650-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:02.824-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9883" version="5" class="vulnerability">
      <metadata>
        <title>The lcd_write function in drivers/usb/misc/usblcd.c in the Linux kernel before 2.6.22-rc7 does not limit the amount of memory used by a caller, which allows local users to cause a denial of service (memory consumption).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3513" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3513"/>
        <description>The lcd_write function in drivers/usb/misc/usblcd.c in the Linux kernel before 2.6.22-rc7 does not limit the amount of memory used by a caller, which allows local users to cause a denial of service (memory consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:56.196-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:44.243-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:51.730-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9883 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:08.570-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:02.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35330"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35339"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35337"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35227"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35043"/>
          <criterion comment="kernel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35276"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:34448"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35366"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35208"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35326"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35345"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9882" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations that target page zero and other low memory addresses, which allows local users to gain privileges by exploiting NULL pointer dereference vulnerabilities, related to (1) the default configuration of the allow_unconfined_mmap_low boolean in SELinux on Red Hat Enterprise Linux (RHEL) 5, (2) an error that causes allow_unconfined_mmap_low to be ignored in the unconfined_t domain, (3) lack of a requirement for the CAP_SYS_RAWIO capability for these mmap operations, and (4) interaction between the mmap_min_addr protection mechanism and certain application programs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2695" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2695"/>
        <description>The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations that target page zero and other low memory addresses, which allows local users to gain privileges by exploiting NULL pointer dereference vulnerabilities, related to (1) the default configuration of the allow_unconfined_mmap_low boolean in SELinux on Red Hat Enterprise Linux (RHEL) 5, (2) an error that causes allow_unconfined_mmap_low to be ignored in the unconfined_t domain, (3) lack of a requirement for the CAP_SYS_RAWIO capability for these mmap operations, and (4) interaction between the mmap_min_addr protection mechanism and certain application programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:21.179-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:43.871-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:51.399-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9882 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:28.061-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:01.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39665"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39142"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39538"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39699"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39518"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39350"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39738"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39663"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39536"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39189"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39141"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9881" version="5" class="vulnerability">
      <metadata>
        <title>Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0234"/>
        <description>Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:04.542-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:43.690-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:51.202-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9881 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:08.788-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:01.664-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="lha is earlier than 0:1.14i-10.2" test_ref="oval:org.mitre.oval:tst:30332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9880" version="5" class="vulnerability">
      <metadata>
        <title>The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6119"/>
        <description>The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:52.977-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:43.402-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:50.850-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9880 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:23.719-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:01.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:988" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal MMSE Dissector Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0507"/>
        <description>Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9879" version="5" class="vulnerability">
      <metadata>
        <title>KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4224" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4224"/>
        <description>KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:28.753-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:43.102-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:50.529-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9879 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:26.551-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:00.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 0:3.3.1-6.el4" test_ref="oval:org.mitre.oval:tst:34380"/>
            <criterion comment="kdebase-devel is earlier than 0:3.3.1-6.el4" test_ref="oval:org.mitre.oval:tst:35343"/>
            <criterion comment="kdelibs is earlier than 6:3.3.1-9.el4" test_ref="oval:org.mitre.oval:tst:35165"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-9.el4" test_ref="oval:org.mitre.oval:tst:35252"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 0:3.5.4-15.el5" test_ref="oval:org.mitre.oval:tst:34844"/>
            <criterion comment="kdebase-devel is earlier than 0:3.5.4-15.el5" test_ref="oval:org.mitre.oval:tst:35321"/>
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:35316"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:35293"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:34994"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9878" version="6" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled causes the skb structure to be freed.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1188"/>
        <description>Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:54.662-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:42.572-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:50.003-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9878 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:15.967-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:59.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40272"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40483"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40310"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40062"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40096"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39895"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40165"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40131"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40380"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39955"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40115"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39718"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40363"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40151"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40182"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40070"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40313"/>
            <criterion comment="kernel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40302"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39440"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39472"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40090"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39519"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39840"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9877" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0093"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:42.802-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:42.338-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:49.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9877 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:47.480-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:59.555-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39831"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39445"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40225"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40023"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9876" version="5" class="vulnerability">
      <metadata>
        <title>The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2438" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2438"/>
        <description>The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:31.682-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:42.109-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:49.509-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9876 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:30.599-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:59.219-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="vim-minimal is earlier than 2:7.0.109-3.el5.3" test_ref="oval:org.mitre.oval:tst:34144"/>
          <criterion comment="vim-enhanced is earlier than 2:7.0.109-3.el5.3" test_ref="oval:org.mitre.oval:tst:33597"/>
          <criterion comment="vim is earlier than 2:7.0.109-3.el5.3" test_ref="oval:org.mitre.oval:tst:33798"/>
          <criterion comment="vim-X11 is earlier than 2:7.0.109-3.el5.3" test_ref="oval:org.mitre.oval:tst:34124"/>
          <criterion comment="vim-common is earlier than 2:7.0.109-3.el5.3" test_ref="oval:org.mitre.oval:tst:33253"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9875" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3738"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:42.973-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:41.545-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:48.915-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9875 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:54.928-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:58.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:33986"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34827"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34839"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34762"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34814"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34694"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34925"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34723"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34968"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34971"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34888"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34868"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34492"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34775"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34828"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34981"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34335"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34957"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34608"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34810"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34667"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9874" version="5" class="vulnerability">
      <metadata>
        <title>The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4307"/>
        <description>The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:32.997-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:41.160-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:48.579-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9874 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:49.612-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:57.963-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39718"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40363"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40151"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40182"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40070"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40313"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40302"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39440"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39472"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40090"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39519"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39840"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9873" version="5" class="vulnerability">
      <metadata>
        <title>The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5947"/>
        <description>The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:56.724-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:40.559-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:48.006-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9873 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:20.196-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:57.256-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35338"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35812"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35754"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35763"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35809"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35651"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35146"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35423"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35775"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35664"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35628"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el4" test_ref="oval:org.mitre.oval:tst:35520"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35267"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35702"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35858"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.8.el4" test_ref="oval:org.mitre.oval:tst:34811"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35523"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35602"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35697"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:34917"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35421"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35528"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35742"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9872" version="5" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5018"/>
        <description>The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:32.387-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:39.910-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:47.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9872 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:02.598-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:56.397-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9871" version="5" class="vulnerability">
      <metadata>
        <title>The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4136"/>
        <description>The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:03.417-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:39.702-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:47.158-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9871 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:21.647-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:56.073-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="luci is earlier than 0:0.10.0-6.el5" test_ref="oval:org.mitre.oval:tst:34653"/>
          <criterion comment="conga is earlier than 0:0.10.0-6.el5" test_ref="oval:org.mitre.oval:tst:34332"/>
          <criterion comment="ricci is earlier than 0:0.10.0-6.el5" test_ref="oval:org.mitre.oval:tst:34712"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9870" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0736"/>
        <description>Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:15.376-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:39.212-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:46.691-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9870 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:18.940-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:55.510-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:987" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal SPNEGO Dissector Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0506" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0506"/>
        <description>The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9869" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4330" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4330"/>
        <description>Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:26.391-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.933-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:46.432-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9869 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:26.730-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:55.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.3-EL3.2" test_ref="oval:org.mitre.oval:tst:33011"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.3-EL3.2" test_ref="oval:org.mitre.oval:tst:32323"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.3-EL4.2" test_ref="oval:org.mitre.oval:tst:33025"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.3-EL4.2" test_ref="oval:org.mitre.oval:tst:32974"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9868" version="5" class="vulnerability">
      <metadata>
        <title>The wait_task_stopped function in the Linux kernel before 2.6.23.8 checks a TASK_TRACED bit instead of an exit_state value, which allows local users to cause a denial of service (machine crash) via unspecified vectors.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5500"/>
        <description>The wait_task_stopped function in the Linux kernel before 2.6.23.8 checks a TASK_TRACED bit instead of an exit_state value, which allows local users to cause a denial of service (machine crash) via unspecified vectors.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:17.346-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:46.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9868 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:23.345-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:54.677-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
          <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9867" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0497" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0497"/>
        <description>Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:06.252-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.351-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:45.708-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9867 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:00.216-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:54.311-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-15.0.3.EL" test_ref="oval:org.mitre.oval:tst:30726"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-15.0.3.EL" test_ref="oval:org.mitre.oval:tst:29909"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.3.EL" test_ref="oval:org.mitre.oval:tst:30725"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.3.EL" test_ref="oval:org.mitre.oval:tst:30253"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-15.0.3.EL" test_ref="oval:org.mitre.oval:tst:30583"/>
          <criterion comment="kernel is earlier than 0:2.4.21-15.0.3.EL" test_ref="oval:org.mitre.oval:tst:29798"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-15.0.3.EL" test_ref="oval:org.mitre.oval:tst:30668"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-15.0.3.EL" test_ref="oval:org.mitre.oval:tst:30738"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-15.0.3.EL" test_ref="oval:org.mitre.oval:tst:30652"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9866" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0766"/>
        <description>Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:24.462-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.111-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:45.452-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9866 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:09.242-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:53.861-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31514"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31448"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31593"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31548"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9865" version="5" class="vulnerability">
      <metadata>
        <title>The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2811"/>
        <description>The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:10.662-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:37.447-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:44.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9865 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:51:56.667-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:53.101-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9864" version="5" class="vulnerability">
      <metadata>
        <title>The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause it to report a file as being owned by "root" instead of "nobody" if the file exists on the server but not on the client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4135"/>
        <description>The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause it to report a file as being owned by "root" instead of "nobody" if the file exists on the server but not on the client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:17.002-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:37.256-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:44.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9864 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:32.902-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:52.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="nfs-utils-lib-devel is earlier than 0:1.0.8-7.2.z2" test_ref="oval:org.mitre.oval:tst:35168"/>
          <criterion comment="nfs-utils-lib is earlier than 0:1.0.8-7.2.z2" test_ref="oval:org.mitre.oval:tst:35408"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9863" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE.  NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2376"/>
        <description>Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE.  NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:51.866-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:36.715-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:43.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9863 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:21.391-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:51.987-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9862" version="5" class="vulnerability">
      <metadata>
        <title>A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory, related to requirements for directory ownership.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2904"/>
        <description>A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory, related to requirements for directory ownership.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:37.822-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:36.494-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:43.707-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9862 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:54.471-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:51.644-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="openssh is earlier than 0:4.3p2-36.el5_4.2" test_ref="oval:org.mitre.oval:tst:39187"/>
          <criterion comment="openssh-askpass is earlier than 0:4.3p2-36.el5_4.2" test_ref="oval:org.mitre.oval:tst:39240"/>
          <criterion comment="openssh-server is earlier than 0:4.3p2-36.el5_4.2" test_ref="oval:org.mitre.oval:tst:38797"/>
          <criterion comment="openssh-clients is earlier than 0:4.3p2-36.el5_4.2" test_ref="oval:org.mitre.oval:tst:39487"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9861" version="5" class="vulnerability">
      <metadata>
        <title>digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1721"/>
        <description>digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:32.582-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:36.135-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:43.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9861 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:38.936-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:50.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cyrus-sasl-plain is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35185"/>
            <criterion comment="cyrus-sasl-md5 is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35067"/>
            <criterion comment="cyrus-sasl-gssapi is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35028"/>
            <criterion comment="cyrus-sasl-devel is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:34649"/>
            <criterion comment="cyrus-sasl is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35113"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cyrus-sasl-ntlm is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:35092"/>
            <criterion comment="cyrus-sasl-sql is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:35100"/>
            <criterion comment="cyrus-sasl-plain is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34748"/>
            <criterion comment="cyrus-sasl-md5 is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34948"/>
            <criterion comment="cyrus-sasl-gssapi is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:35102"/>
            <criterion comment="cyrus-sasl-devel is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34645"/>
            <criterion comment="cyrus-sasl is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34338"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9860" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4309"/>
        <description>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:35.483-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:35.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:42.889-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9860 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:23.820-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:50.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37666"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37742"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37538"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37806"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37593"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37167"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37819"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37707"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37868"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37115"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:36966"/>
            <criterion comment="net-snmp is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37758"/>
            <criterion comment="net-snmp-libs is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37686"/>
            <criterion comment="net-snmp-perl is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37927"/>
            <criterion comment="net-snmp-devel is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:986" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal AIM Dissector Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0505" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0505"/>
        <description>The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9859" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2063"/>
        <description>Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:17.627-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:35.122-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:42.322-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9859 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:47.992-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:49.617-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40725"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40543"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40781"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40212"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40761"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40021"/>
            <criterion comment="samba is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tdb-tools is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40785"/>
            <criterion comment="libtdb-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:39928"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40808"/>
            <criterion comment="samba3x-common is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40403"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40124"/>
            <criterion comment="samba3x-doc is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40792"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40636"/>
            <criterion comment="libtalloc-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40508"/>
            <criterion comment="libtdb is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40589"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40500"/>
            <criterion comment="samba3x-client is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40646"/>
            <criterion comment="samba3x is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40660"/>
            <criterion comment="libtalloc is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40439"/>
            <criterion comment="samba3x-swat is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40724"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40663"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40822"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40799"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40481"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:39867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9858" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2933" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2933"/>
        <description>Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:13.577-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:34.202-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:41.736-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9858 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:40.490-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:48.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-mysql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32711"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32166"/>
            <criterion comment="imap is earlier than 1:2002d-12" test_ref="oval:org.mitre.oval:tst:31804"/>
            <criterion comment="imap-devel is earlier than 1:2002d-12" test_ref="oval:org.mitre.oval:tst:32091"/>
            <criterion comment="php is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32579"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32613"/>
            <criterion comment="imap-utils is earlier than 1:2002d-12" test_ref="oval:org.mitre.oval:tst:32441"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32425"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32107"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32695"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31742"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32509"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32606"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32503"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32185"/>
            <criterion comment="libc-client is earlier than 0:2002e-14" test_ref="oval:org.mitre.oval:tst:32375"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32639"/>
            <criterion comment="php is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32546"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32577"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32236"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32578"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32591"/>
            <criterion comment="libc-client-devel is earlier than 0:2002e-14" test_ref="oval:org.mitre.oval:tst:32344"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32707"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32547"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31727"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9857" version="5" class="vulnerability">
      <metadata>
        <title>The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3732"/>
        <description>The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:39.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:33.922-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:41.492-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9857 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:47.575-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:48.577-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="ipsec-tools is earlier than 0:0.2.5-0.7.rhel3.3" test_ref="oval:org.mitre.oval:tst:32025"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="ipsec-tools is earlier than 0:0.3.3-6.rhel4.1" test_ref="oval:org.mitre.oval:tst:32632"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9856" version="5" class="vulnerability">
      <metadata>
        <title>The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0433" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0433"/>
        <description>The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:26.254-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:33.724-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:41.269-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9856 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:08.280-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:48.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:39952"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:40361"/>
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:40102"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9855" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0091"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:46.228-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:33.496-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:40.993-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9855 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:04.411-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:47.897-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39831"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:39445"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40225"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40023"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.11.b16.el5" test_ref="oval:org.mitre.oval:tst:40307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9854" version="5" class="vulnerability">
      <metadata>
        <title>Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0494"/>
        <description>Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:02.913-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:33.309-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:40.758-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9854 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:57.291-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:47.620-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gnome-vfs2-devel is earlier than 0:2.2.5-2E.1" test_ref="oval:org.mitre.oval:tst:30568"/>
          <criterion comment="gnome-vfs2 is earlier than 0:2.2.5-2E.1" test_ref="oval:org.mitre.oval:tst:30787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9853" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1461"/>
        <description>Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:12.258-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:33.072-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:40.507-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9853 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:24.939-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:47.233-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9852" version="5" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1769"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:17.382-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:32.818-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:40.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9852 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:54.383-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:46.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-11.EL3" test_ref="oval:org.mitre.oval:tst:31585"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-12.EL4" test_ref="oval:org.mitre.oval:tst:31556"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9851" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1423" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1423"/>
        <description>Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:32.959-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:32.531-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:39.925-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9851 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:43.147-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:46.327-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36659"/>
            <criterion comment="libvorbis is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36699"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36519"/>
            <criterion comment="libvorbis is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36387"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36439"/>
            <criterion comment="libvorbis is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36710"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9850" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1938" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1938"/>
        <description>Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:28.542-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:32.289-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:39.672-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9850 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:02.526-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:45.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32590"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32299"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9849" version="5" class="vulnerability">
      <metadata>
        <title>Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2776"/>
        <description>Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:02.200-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:31.726-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:39.158-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9849 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:45.820-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:45.288-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9848" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1010"/>
        <description>Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:22.001-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:31.544-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:38.914-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9848 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:41.403-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:44.965-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="zip is earlier than 0:2.3-16.1" test_ref="oval:org.mitre.oval:tst:31068"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9847" version="3" class="vulnerability">
      <metadata>
        <title>The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0628"/>
        <description>The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:35.622-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:31.316-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:38.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
        <criteria operator="OR">
          <criterion comment="java-1.6.0-bea-demo is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36331"/>
          <criterion comment="java-1.6.0-bea-devel is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36423"/>
          <criterion comment="java-1.6.0-bea is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36195"/>
          <criterion comment="java-1.6.0-bea-src is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36590"/>
          <criterion comment="java-1.6.0-bea-missioncontrol is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36683"/>
          <criterion comment="java-1.6.0-bea-jdbc is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36658"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9846" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6063"/>
        <description>Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:29.687-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:30.659-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:38.052-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9846 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:28.362-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:44.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37931"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37846"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37817"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37663"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37799"/>
            <criterion comment="kernel is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37028"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37885"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37981"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37117"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36192"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36176"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36335"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36430"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35944"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36215"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36409"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35484"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35974"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35791"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36150"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9845" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1686"/>
        <description>Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:01.759-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:30.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:37.774-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9845 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:56.618-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:43.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gedit is earlier than 1:2.2.2-4.rhel3" test_ref="oval:org.mitre.oval:tst:31476"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gedit is earlier than 1:2.8.1-4" test_ref="oval:org.mitre.oval:tst:31796"/>
            <criterion comment="gedit-devel is earlier than 1:2.8.1-4" test_ref="oval:org.mitre.oval:tst:31886"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9844" version="5" class="vulnerability">
      <metadata>
        <title>KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2449" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2449"/>
        <description>KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:45.232-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:30.235-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:37.569-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9844 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:56.081-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:43.477-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdebase is earlier than 6:3.3.1-5.12" test_ref="oval:org.mitre.oval:tst:32706"/>
          <criterion comment="kdebase-devel is earlier than 6:3.3.1-5.12" test_ref="oval:org.mitre.oval:tst:32662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9843" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4568"/>
        <description>Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:02.251-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:29.685-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:37.007-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9843 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:26.610-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:42.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9842" version="5" class="vulnerability">
      <metadata>
        <title>gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0423" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0423"/>
        <description>gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:45.283-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:29.269-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:36.580-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9842 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:43.258-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:42.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39911"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40093"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40218"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40181"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40052"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39983"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39933"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40004"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40214"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39974"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40080"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40176"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40248"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40202"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40141"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39917"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40306"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39993"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9841" version="5" class="vulnerability">
      <metadata>
        <title>Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6113"/>
        <description>Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:20.400-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:28.758-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:36.202-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9841 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:33.180-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:41.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9840" version="5" class="vulnerability">
      <metadata>
        <title>The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, allows HVM guest users to access arbitrary physical memory by triggering certain mapping operations.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6416"/>
        <description>The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, allows HVM guest users to access arbitrary physical memory by triggering certain mapping operations.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:06.592-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:28.433-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:35.804-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9840 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:19.226-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:41.198-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36030"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35766"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36138"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36062"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35611"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35990"/>
          <criterion comment="kernel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35969"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36085"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36026"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36084"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36097"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36035"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:984" version="4" class="vulnerability">
      <metadata>
        <title>Racoon Denial of Service via Large Length Field</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0403" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0403"/>
        <description>Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:52.316-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:12.021-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.756-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:54:36.823-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:48.066-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ipsec-tools version is less than 0.2.5-0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1430"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="racoon is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9839" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5393" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5393"/>
        <description>Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:25.655-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:27.692-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:35.083-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9839 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:50.300-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:40.015-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35542"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35314"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35233"/>
            <criterion comment="cups-libs is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35218"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35248"/>
            <criterion comment="cups-devel is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35491"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:34644"/>
            <criterion comment="xpdf is earlier than 0:2.02-11.el3" test_ref="oval:org.mitre.oval:tst:35634"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35275"/>
            <criterion comment="cups is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35533"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:34998"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35446"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35156"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35404"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35455"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35415"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35178"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.1" test_ref="oval:org.mitre.oval:tst:35574"/>
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:34735"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35585"/>
            <criterion comment="xpdf is earlier than 1:3.00-14.el4" test_ref="oval:org.mitre.oval:tst:35315"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35591"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35283"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35537"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-5.el5_1" test_ref="oval:org.mitre.oval:tst:35714"/>
            <criterion comment="cups-lpd is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35274"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35509"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-5.el5_1" test_ref="oval:org.mitre.oval:tst:35722"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35549"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35527"/>
            <criterion comment="cups-libs is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35427"/>
            <criterion comment="tetex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35459"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34727"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35496"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35498"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35147"/>
            <criterion comment="cups-devel is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35508"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35407"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34618"/>
            <criterion comment="cups is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35530"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9838" version="5" class="vulnerability">
      <metadata>
        <title>The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX, which can cause ipt_recent netfilter rules to block too early, a different vulnerability than CVE-2005-2872.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2873" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2873"/>
        <description>The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX, which can cause ipt_recent netfilter rules to block too early, a different vulnerability than CVE-2005-2872.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:39.562-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:27.383-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:34.705-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9838 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:14.728-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:39.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30189"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30542"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30504"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30169"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29589"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30432"/>
          <criterion comment="kernel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29669"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30424"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30299"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30268"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9837" version="5" class="vulnerability">
      <metadata>
        <title>Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1577" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1577"/>
        <description>Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:55.117-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:27.162-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:34.470-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9837 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:48.413-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:39.227-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-16.RHEL3" test_ref="oval:org.mitre.oval:tst:38743"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-10.RHEL4.3" test_ref="oval:org.mitre.oval:tst:38662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9836" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3243"/>
        <description>Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:11.872-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:26.876-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:34.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9836 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:32.790-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:38.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32189"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32138"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32341"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32202"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9835" version="5" class="vulnerability">
      <metadata>
        <title>The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0167" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0167"/>
        <description>The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:00.189-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:26.620-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:33.827-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9835 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:37.709-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:38.364-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9834" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0175"/>
        <description>Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:58.954-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:26.140-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:33.343-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9834 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:56.555-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:37.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39934"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40184"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40133"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39775"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40360"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40059"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39946"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40114"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.19-1.el4" test_ref="oval:org.mitre.oval:tst:40284"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40081"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40250"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40304"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40345"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40183"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:39945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40265"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:39621"/>
            <criterion comment="firefox is earlier than 0:3.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40064"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9833" version="5" class="vulnerability">
      <metadata>
        <title>Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1926" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1926"/>
        <description>Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:38.580-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:25.908-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:33.147-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9833 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:06.706-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:37.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="util-linux is earlier than 0:2.12a-24.el4" test_ref="oval:org.mitre.oval:tst:38784"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9832" version="5" class="vulnerability">
      <metadata>
        <title>The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through 2.6.33, and possibly other versions, allows local users to cause a denial of service (kernel OOPS) by sending datagrams through AF_TIPC before entering network mode, which triggers a NULL pointer dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1187"/>
        <description>The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through 2.6.33, and possibly other versions, allows local users to cause a denial of service (kernel OOPS) by sending datagrams through AF_TIPC before entering network mode, which triggers a NULL pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:57.277-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:25.585-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:32.416-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9832 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:58.742-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:36.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40501"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40283"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40807"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40842"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40793"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40732"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40830"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40349"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39978"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39896"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40791"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40580"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9831" version="5" class="vulnerability">
      <metadata>
        <title>nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "multiple packets per netlink message", and (3) bridged packets, which trigger a NULL pointer dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1496" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1496"/>
        <description>nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "multiple packets per netlink message", and (3) bridged packets, which trigger a NULL pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:20.253-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:25.278-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:32.091-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9831 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:57.156-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:36.404-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34146"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34219"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34205"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:33862"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34224"/>
          <criterion comment="kernel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:33837"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34231"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34073"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:33861"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:33594"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34059"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9830" version="5" class="vulnerability">
      <metadata>
        <title>Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2014"/>
        <description>Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:25.497-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:25.002-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:31.815-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9830 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:42.262-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:35.984-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-1.30E.1" test_ref="oval:org.mitre.oval:tst:31680"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-2.4E.1" test_ref="oval:org.mitre.oval:tst:31717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9829" version="5" class="vulnerability">
      <metadata>
        <title>The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0006"/>
        <description>The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:42.131-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:24.559-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:31.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9829 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:48.237-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:35.392-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33775"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33751"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33264"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33777"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33668"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33639"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33564"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33538"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33494"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33717"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33839"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33412"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33730"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33902"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33740"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33736"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33914"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33489"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33621"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33879"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9828" version="3" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect.  NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6637" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6637"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect.  NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:13.337-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:24.312-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:31.119-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criterion comment="flash-plugin is earlier than 0:9.0.124.0-1.el3.with.oss" test_ref="oval:org.mitre.oval:tst:36002"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criterion comment="flash-plugin is earlier than 0:9.0.124.0-1.el4" test_ref="oval:org.mitre.oval:tst:36397"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criterion comment="flash-plugin is earlier than 0:9.0.124.0-1.el5" test_ref="oval:org.mitre.oval:tst:36022"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9827" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3469"/>
        <description>Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:39.932-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:24.090-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:30.859-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9827 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:30.561-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:35.064-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37045"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37456"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:36967"/>
          <criterion comment="mysql-server is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37224"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9826" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0594"/>
        <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:40.916-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:23.741-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:30.560-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9826 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:43.850-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:34.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.4.2-3.0.2" test_ref="oval:org.mitre.oval:tst:30703"/>
          <criterion comment="mozilla is earlier than 37:1.4.2-3.0.2" test_ref="oval:org.mitre.oval:tst:30682"/>
          <criterion comment="mozilla-chat is earlier than 37:1.4.2-3.0.2" test_ref="oval:org.mitre.oval:tst:29813"/>
          <criterion comment="mozilla-mail is earlier than 37:1.4.2-3.0.2" test_ref="oval:org.mitre.oval:tst:29961"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.2-3.0.2" test_ref="oval:org.mitre.oval:tst:30646"/>
          <criterion comment="mozilla-nss is earlier than 37:1.4.2-3.0.2" test_ref="oval:org.mitre.oval:tst:30390"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.4.2-3.0.2" test_ref="oval:org.mitre.oval:tst:30528"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.4.2-3.0.2" test_ref="oval:org.mitre.oval:tst:30482"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.2-3.0.2" test_ref="oval:org.mitre.oval:tst:30659"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9825" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1457"/>
        <description>Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:01.294-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:23.494-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:30.308-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9825 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:41.586-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:34.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9824" version="5" class="vulnerability">
      <metadata>
        <title>cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1863"/>
        <description>cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:19.575-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:23.126-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:29.870-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9824 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:06.406-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:33.675-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-67.ent" test_ref="oval:org.mitre.oval:tst:34223"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.46-67.ent" test_ref="oval:org.mitre.oval:tst:34500"/>
            <criterion comment="httpd is earlier than 0:2.0.46-67.ent" test_ref="oval:org.mitre.oval:tst:34481"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34166"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34468"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34603"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34461"/>
            <criterion comment="httpd is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34632"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34730"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34677"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34399"/>
            <criterion comment="httpd is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34605"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9823" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1932" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1932"/>
        <description>Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:21.198-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:22.833-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:29.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9823 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:52.980-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:33.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32590"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32299"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9822" version="5" class="vulnerability">
      <metadata>
        <title>sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4576" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4576"/>
        <description>sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:38.095-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:22.515-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:29.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9822 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:29.941-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:32.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:37458"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:38105"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:38024"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:38100"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:37636"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:38034"/>
          <criterion comment="kernel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:37781"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:38076"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:37945"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:38013"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:37261"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.22.el5" test_ref="oval:org.mitre.oval:tst:37532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9821" version="5" class="vulnerability">
      <metadata>
        <title>The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4683" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4683"/>
        <description>The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:21.139-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:22.218-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:28.933-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9821 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:46.040-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:32.359-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9820" version="5" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2466"/>
        <description>The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:30.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:21.658-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:28.429-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9820 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:59.508-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:31.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38881"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38851"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38690"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38366"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38475"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38924"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38923"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38918"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38811"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38644"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38772"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:37948"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:38809"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38947"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38194"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38876"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38504"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38249"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38575"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38853"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:982" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal Denial of Service via SIP Messages</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0504"/>
        <description>Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9819" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1689"/>
        <description>Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:44.542-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:21.337-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:28.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9819 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:53.520-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:31.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31712"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31065"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31933"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31927"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31772"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31800"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31846"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31172"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31706"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9818" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1312"/>
        <description>Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:59.412-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:20.808-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:27.568-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9818 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:02.938-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:30.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38597"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38375"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38403"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38521"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38542"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:37726"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38677"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38096"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38577"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38540"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38716"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38634"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38190"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38596"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38685"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38697"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9817" version="5" class="vulnerability">
      <metadata>
        <title>The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739"/>
        <description>The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:40.844-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:20.317-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:27.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9817 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:26.577-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:29.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9816" version="5" class="vulnerability">
      <metadata>
        <title>The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2958"/>
        <description>The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:55.106-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:20.129-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:26.828-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9816 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:46.674-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:29.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criterion comment="dnsmasq is earlier than 0:2.45-1.1.el5_3" test_ref="oval:org.mitre.oval:tst:38956"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9815" version="5" class="vulnerability">
      <metadata>
        <title>js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841"/>
        <description>js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:17.588-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:19.589-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:26.339-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9815 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:22.619-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:28.697-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38336"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38452"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38736"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38742"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38069"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38264"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38724"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38791"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38432"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:37902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38280"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38793"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38531"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38655"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38828"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38213"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9814" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5512" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5512"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:59.318-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:18.500-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:25.657-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9814 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:12.276-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:27.854-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38137"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37999"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37907"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37709"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38092"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37745"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38039"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38062"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38073"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38071"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:37200"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37812"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37869"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37789"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37395"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:38053"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:37631"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38114"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37737"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9813" version="3" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods.  NOTE: this issue might be subsumed by CVE-2008-0655.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5659" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5659"/>
        <description>Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods.  NOTE: this issue might be subsumed by CVE-2008-0655.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:46.267-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:18.213-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:25.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:8.1.2-1.el3.6" test_ref="oval:org.mitre.oval:tst:36324"/>
            <criterion comment="acroread is earlier than 0:8.1.2-1.el3.6" test_ref="oval:org.mitre.oval:tst:36153"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:8.1.2-1.el4.2" test_ref="oval:org.mitre.oval:tst:36156"/>
            <criterion comment="acroread is earlier than 0:8.1.2-1.el4.2" test_ref="oval:org.mitre.oval:tst:36293"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:8.1.2-1.el5.3" test_ref="oval:org.mitre.oval:tst:35792"/>
            <criterion comment="acroread is earlier than 0:8.1.2-1.el5.3" test_ref="oval:org.mitre.oval:tst:35912"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9812" version="5" class="vulnerability">
      <metadata>
        <title>libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3281"/>
        <description>libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:20.837-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:17.819-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:24.968-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9812 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:01.796-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:27.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-11" test_ref="oval:org.mitre.oval:tst:37109"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-11" test_ref="oval:org.mitre.oval:tst:37627"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-11" test_ref="oval:org.mitre.oval:tst:37621"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.3" test_ref="oval:org.mitre.oval:tst:36654"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.3" test_ref="oval:org.mitre.oval:tst:37135"/>
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.3" test_ref="oval:org.mitre.oval:tst:37610"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.4" test_ref="oval:org.mitre.oval:tst:37604"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.4" test_ref="oval:org.mitre.oval:tst:37085"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.4" test_ref="oval:org.mitre.oval:tst:37551"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9811" version="5" class="vulnerability">
      <metadata>
        <title>Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0089"/>
        <description>The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:14.550-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:17.516-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:24.650-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9811 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:52.661-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:26.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.1" test_ref="oval:org.mitre.oval:tst:31354"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.1" test_ref="oval:org.mitre.oval:tst:31195"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.1" test_ref="oval:org.mitre.oval:tst:31366"/>
            <criterion comment="python is earlier than 0:2.2.3-6.1" test_ref="oval:org.mitre.oval:tst:31351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:30896"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:31368"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:30806"/>
            <criterion comment="python is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:31194"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:30393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9810" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3185"/>
        <description>Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:16.557-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:17.233-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:24.374-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9810 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:38.777-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:26.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wget is earlier than 0:1.10.2-0.30E" test_ref="oval:org.mitre.oval:tst:32350"/>
            <criterion comment="curl-devel is earlier than 0:7.10.6-7.rhel3" test_ref="oval:org.mitre.oval:tst:32411"/>
            <criterion comment="curl is earlier than 0:7.10.6-7.rhel3" test_ref="oval:org.mitre.oval:tst:32351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wget is earlier than 0:1.10.2-0.40E" test_ref="oval:org.mitre.oval:tst:32340"/>
            <criterion comment="curl-devel is earlier than 0:7.12.1-6.rhel4" test_ref="oval:org.mitre.oval:tst:32364"/>
            <criterion comment="curl is earlier than 0:7.12.1-6.rhel4" test_ref="oval:org.mitre.oval:tst:32423"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9809" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and causes an exported directory to be remounted read-only.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3468" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3468"/>
        <description>Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and causes an exported directory to be remounted read-only.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:01.927-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:16.896-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:23.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9809 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:34.172-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:25.612-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32576"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32814"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32958"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32801"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32865"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32880"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32747"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32200"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32838"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9808" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1316"/>
        <description>Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:51.836-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:16.602-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:23.672-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9808 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:02.927-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:25.227-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:31052"/>
          <criterion comment="mozilla is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:31079"/>
          <criterion comment="mozilla-chat is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:31147"/>
          <criterion comment="mozilla-mail is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:30749"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:31309"/>
          <criterion comment="mozilla-devel is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:31267"/>
          <criterion comment="mozilla-nss is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:30958"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:30815"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:31304"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.7" test_ref="oval:org.mitre.oval:tst:31266"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9807" version="5" class="vulnerability">
      <metadata>
        <title>The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1168"/>
        <description>The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:48.714-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:16.272-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:23.333-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9807 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:31.882-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:24.689-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40554"/>
            <criterion comment="perl is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40615"/>
            <criterion comment="perl-CPAN is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:39713"/>
            <criterion comment="perl-CGI is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40065"/>
            <criterion comment="perl-DB_File is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40367"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 3:5.8.5-53.el4" test_ref="oval:org.mitre.oval:tst:40654"/>
            <criterion comment="perl is earlier than 3:5.8.5-53.el4" test_ref="oval:org.mitre.oval:tst:40417"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:40657"/>
            <criterion comment="perl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:39926"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9806" version="5" class="vulnerability">
      <metadata>
        <title>The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2664"/>
        <description>The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:16.762-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:15.967-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:23.051-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9806 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:17.359-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:24.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:38809"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38249"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38575"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38853"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9805" version="5" class="vulnerability">
      <metadata>
        <title>cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0806"/>
        <description>cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:11.466-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:15.744-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:22.779-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9805 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:40.186-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:23.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mkisofs is earlier than 8:2.01.0.a32-0.EL3.2" test_ref="oval:org.mitre.oval:tst:30433"/>
          <criterion comment="cdrecord is earlier than 8:2.01.0.a32-0.EL3.2" test_ref="oval:org.mitre.oval:tst:30490"/>
          <criterion comment="cdrtools is earlier than 8:2.01.0.a32-0.EL3.2" test_ref="oval:org.mitre.oval:tst:30552"/>
          <criterion comment="cdrecord-devel is earlier than 8:2.01.0.a32-0.EL3.2" test_ref="oval:org.mitre.oval:tst:30505"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9804" version="5" class="vulnerability">
      <metadata>
        <title>The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4769"/>
        <description>The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:32.588-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:15.294-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:22.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9804 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:44.458-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:23.332-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35948"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35993"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36045"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35949"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36098"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36066"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35942"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36105"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35835"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35597"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35261"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35907"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35319"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35123"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35894"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35781"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36109"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35308"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35856"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36044"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9803" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1835"/>
        <description>Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:18.299-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:14.731-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:21.767-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9803 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:00.481-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:22.636-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38336"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38452"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38736"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38742"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38069"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38264"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38724"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38791"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38432"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:37902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38280"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38793"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38531"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38655"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38828"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38213"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9802" version="5" class="vulnerability">
      <metadata>
        <title>Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0935" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0935"/>
        <description>Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:55.937-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:14.524-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:21.535-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9802 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:16.267-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:22.348-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.1" test_ref="oval:org.mitre.oval:tst:30617"/>
          <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.1" test_ref="oval:org.mitre.oval:tst:30534"/>
          <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.1" test_ref="oval:org.mitre.oval:tst:30077"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9801" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0557" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0557"/>
        <description>Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:03.371-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:14.332-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:21.331-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9801 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:11.571-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:22.072-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="sox is earlier than 0:12.17.4-4.3" test_ref="oval:org.mitre.oval:tst:30502"/>
          <criterion comment="sox-devel is earlier than 0:12.17.4-4.3" test_ref="oval:org.mitre.oval:tst:30810"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9800" version="5" class="vulnerability">
      <metadata>
        <title>Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow.  NOTE: the role of the channel_process function was not specified by the original researcher.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1803"/>
        <description>Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow.  NOTE: the role of the channel_process function was not specified by the original researcher.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:19.983-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:14.156-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:21.139-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9800 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:52.699-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:21.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criterion comment="rdesktop is earlier than 0:1.4.1-6" test_ref="oval:org.mitre.oval:tst:37100"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:980" version="3" class="vulnerability">
      <metadata>
        <title>NTLM Authentication BO in Squid Web Proxy Cache</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0541" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0541"/>
        <description>Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected the local_port entity for a linux-def:inetlisteningservers_object.  Local_port was given a datatype of 'int'." date="2010-09-03T10:43:00.355-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-03T10:47:03.463-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:47.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="squid version is less than 2.5.STABLE3-6.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1361"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1360"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9799" version="5" class="vulnerability">
      <metadata>
        <title>The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite loop or crash) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6116"/>
        <description>The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite loop or crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:19.181-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:13.793-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:20.781-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9799 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:16.167-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:21.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9798" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1003"/>
        <description>Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:38.799-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:12.831-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:19.840-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9798 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:04.189-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:20.005-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33447"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33884"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33550"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33984"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33936"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33976"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33799"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33867"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33958"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33791"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33929"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33764"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33070"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33716"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33788"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33928"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33930"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33951"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33950"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33932"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33656"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33963"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33466"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33846"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33660"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33687"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33689"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33499"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33719"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33696"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33811"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33258"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33567"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33738"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33938"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33663"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33066"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33875"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33789"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33829"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33434"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33704"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33790"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33886"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33982"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33715"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33856"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33815"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33470"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33864"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33546"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33718"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33954"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33629"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33876"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9797" version="5" class="vulnerability">
      <metadata>
        <title>zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0758"/>
        <description>zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:03.149-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:12.526-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:19.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9797 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:26.391-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:19.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bzip2-devel is earlier than 0:1.0.2-11.EL3.4" test_ref="oval:org.mitre.oval:tst:31970"/>
            <criterion comment="bzip2 is earlier than 0:1.0.2-11.EL3.4" test_ref="oval:org.mitre.oval:tst:31944"/>
            <criterion comment="gzip is earlier than 0:1.3.3-12.rhel3" test_ref="oval:org.mitre.oval:tst:30880"/>
            <criterion comment="bzip2-libs is earlier than 0:1.0.2-11.EL3.4" test_ref="oval:org.mitre.oval:tst:31594"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bzip2-devel is earlier than 0:1.0.2-13.EL4.3" test_ref="oval:org.mitre.oval:tst:31440"/>
            <criterion comment="bzip2 is earlier than 0:1.0.2-13.EL4.3" test_ref="oval:org.mitre.oval:tst:31845"/>
            <criterion comment="gzip is earlier than 0:1.3.3-15.rhel4" test_ref="oval:org.mitre.oval:tst:31566"/>
            <criterion comment="bzip2-libs is earlier than 0:1.0.2-13.EL4.3" test_ref="oval:org.mitre.oval:tst:30992"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9796" version="5" class="vulnerability">
      <metadata>
        <title>Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0354" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0354"/>
        <description>Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:26.576-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:12.189-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:19.172-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9796 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:51.321-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:19.066-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9795" version="5" class="vulnerability">
      <metadata>
        <title>Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1056"/>
        <description>Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:14.919-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:11.764-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:18.717-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9795 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:01.552-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:18.496-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9794" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5960" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5960"/>
        <description>Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:26.912-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:11.231-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:18.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9794 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:19.554-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:17.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35338"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35812"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35754"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35763"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35809"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35651"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35146"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35423"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35775"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35664"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35628"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el4" test_ref="oval:org.mitre.oval:tst:35520"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35267"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35702"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35858"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.8.el4" test_ref="oval:org.mitre.oval:tst:34811"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35523"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35602"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35697"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:34917"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35421"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35528"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35742"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9793" version="5" class="vulnerability">
      <metadata>
        <title>The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3657" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3657"/>
        <description>The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:08.720-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:10.772-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:17.698-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9793 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:58.703-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:17.210-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37462"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37630"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36810"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36902"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37678"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37674"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37720"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37735"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37344"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37697"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37273"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37563"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37438"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37757"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37463"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37172"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9792" version="5" class="vulnerability">
      <metadata>
        <title>The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3799"/>
        <description>The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:08.940-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:10.000-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:16.944-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9792 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:42.907-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:16.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35216"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35012"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34787"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35164"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34818"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35171"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34820"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35008"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34796"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35363"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35010"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35249"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34683"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34365"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34976"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35087"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35298"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35289"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35309"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35263"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35279"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34964"/>
            <criterion comment="php-common is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34896"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35084"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35078"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34802"/>
            <criterion comment="php is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35270"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35361"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34769"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35108"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35037"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34943"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34689"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35221"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35077"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34934"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35170"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34376"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34764"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9791" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3984"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:18.312-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:09.523-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:16.447-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9791 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:09.990-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:15.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39610"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39451"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39678"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39628"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39624"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39524"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39588"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39651"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:38845"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39752"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.16-4.el4" test_ref="oval:org.mitre.oval:tst:39002"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39832"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39735"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39283"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39646"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39176"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39656"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39838"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39032"/>
            <criterion comment="firefox is earlier than 0:3.0.16-1.el5_4" test_ref="oval:org.mitre.oval:tst:39721"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9790" version="5" class="vulnerability">
      <metadata>
        <title>OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3245"/>
        <description>OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:04.249-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:09.245-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:16.153-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9790 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:45.093-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:15.097-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="openssl096b is earlier than 0:0.9.6b-16.50" test_ref="oval:org.mitre.oval:tst:40235"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="openssl096b is earlier than 0:0.9.6b-22.46.el4_8.1" test_ref="oval:org.mitre.oval:tst:40149"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:39952"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:40361"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:40102"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:979" version="1" class="vulnerability">
      <metadata>
        <title>Utempter Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0233"/>
        <description>Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="utempter version is less than 0.5.5-1.3EL.0" negate="false" test_ref="oval:org.mitre.oval:tst:1366"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/sbin/utempter is executable">
            <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1365"/>
            <criteria operator="OR" comment="/usr/sbin/utempter is executable">
              <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1364"/>
              <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1363"/>
              <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1362"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9789" version="5" class="vulnerability">
      <metadata>
        <title>The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3374"/>
        <description>The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:59.938-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:08.914-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:15.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9789 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:42.447-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:14.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9788" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2193"/>
        <description>Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:12.247-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:08.547-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:15.536-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9788 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:44.255-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:14.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="libtiff is earlier than 0:3.6.1-12.el4_7.2" test_ref="oval:org.mitre.oval:tst:37555"/>
          <criterion comment="libtiff-devel is earlier than 0:3.6.1-12.el4_7.2" test_ref="oval:org.mitre.oval:tst:37573"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9787" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2152" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2152"/>
        <description>Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:00.696-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:06.466-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:13.342-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9787 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:21.546-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:11.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-42.2.0.EL3" test_ref="oval:org.mitre.oval:tst:37041"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-42.2.0.EL3" test_ref="oval:org.mitre.oval:tst:37101"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-42.2.0.EL3" test_ref="oval:org.mitre.oval:tst:37231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37131"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36855"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37023"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37014"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36137"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36217"/>
            <criterion comment="openoffice.org2-draw is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37001"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36763"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36900"/>
            <criterion comment="openoffice.org2-base is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36904"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37102"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:37327"/>
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:37258"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36971"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36698"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37065"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36143"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37128"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37134"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37093"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36815"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36342"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37034"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36655"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36942"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36897"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37055"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37040"/>
            <criterion comment="openoffice.org2 is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37021"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37103"/>
            <criterion comment="openoffice.org2-impress is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36121"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36947"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37015"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37052"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37077"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36551"/>
            <criterion comment="openoffice.org2-calc is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37078"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36165"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36997"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37121"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36911"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36682"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36825"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36739"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37097"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36848"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36841"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:37002"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37142"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36872"/>
            <criterion comment="openoffice.org2-testtools is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37122"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:36748"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37004"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36830"/>
            <criterion comment="openoffice.org2-core is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36693"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36923"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36982"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37080"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36346"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37019"/>
            <criterion comment="openoffice.org2-math is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37076"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37072"/>
            <criterion comment="openoffice.org2-writer is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37088"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37166"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37187"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37170"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37123"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37214"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37151"/>
            <criterion comment="openoffice.org is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37303"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37161"/>
            <criterion comment="openoffice.org-writer is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37011"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36920"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37334"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37136"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37183"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36862"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36809"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37264"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37095"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37090"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37053"/>
            <criterion comment="openoffice.org-javafilter is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37308"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37009"/>
            <criterion comment="openoffice.org-testtools is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36832"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36882"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36676"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37216"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37256"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37150"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37062"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37025"/>
            <criterion comment="openoffice.org-base is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37325"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36746"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36993"/>
            <criterion comment="openoffice.org-core is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36901"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37311"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36621"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37298"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37339"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37184"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37220"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36497"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37147"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37270"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37099"/>
            <criterion comment="openoffice.org-pyuno is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37278"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37241"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37169"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37338"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36994"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37310"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37137"/>
            <criterion comment="openoffice.org-sdk is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37110"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37194"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37221"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37030"/>
            <criterion comment="openoffice.org-draw is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37210"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37130"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37324"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37244"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37277"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37175"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36987"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36625"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36795"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37168"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37329"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37177"/>
            <criterion comment="openoffice.org-calc is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37006"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37132"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37116"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36675"/>
            <criterion comment="openoffice.org-headless is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37212"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37235"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37042"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37211"/>
            <criterion comment="openoffice.org-math is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37290"/>
            <criterion comment="openoffice.org-impress is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36953"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37186"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9786" version="5" class="vulnerability">
      <metadata>
        <title>Multiple "overflows" in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1017"/>
        <description>Multiple "overflows" in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:58.694-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:06.084-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:12.947-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9786 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:35.424-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:11.550-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:31101"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30944"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30205"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30752"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30999"/>
          <criterion comment="kernel is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30940"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:31177"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30903"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30786"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9785" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1767"/>
        <description>Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:44.759-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:05.731-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:12.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9785 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:36.607-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:11.015-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxslt-devel is earlier than 0:1.0.33-6" test_ref="oval:org.mitre.oval:tst:36611"/>
            <criterion comment="libxslt is earlier than 0:1.0.33-6" test_ref="oval:org.mitre.oval:tst:36656"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxslt-devel is earlier than 0:1.1.11-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36213"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.11-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36777"/>
            <criterion comment="libxslt is earlier than 0:1.1.11-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36639"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-2.el5_1.1" test_ref="oval:org.mitre.oval:tst:36716"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-2.el5_1.1" test_ref="oval:org.mitre.oval:tst:36669"/>
            <criterion comment="libxslt is earlier than 0:1.1.17-2.el5_1.1" test_ref="oval:org.mitre.oval:tst:36648"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9784" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2704"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:54.727-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:05.238-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:12.107-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9784 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:40.755-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:10.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32169"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31729"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32242"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32151"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32014"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32144"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32068"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32248"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32293"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32244"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32012"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:31897"/>
            <criterion comment="thunderbird is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:31477"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32300"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32226"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32289"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32170"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32150"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32302"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32090"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32209"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9783" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1111"/>
        <description>Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:18.907-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:04.980-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:11.812-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9783 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:52.866-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:09.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cpio is earlier than 0:2.5-4.RHEL3" test_ref="oval:org.mitre.oval:tst:31643"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cpio is earlier than 0:2.5-8.RHEL4" test_ref="oval:org.mitre.oval:tst:30793"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9782" version="5" class="vulnerability">
      <metadata>
        <title>The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.  NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1558"/>
        <description>The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.  NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:09.833-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:04.090-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:10.847-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9782 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:51.507-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:08.786-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34409"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34257"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34432"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33988"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33721"/>
            <criterion comment="evolution is earlier than 0:1.4.5-20.el3" test_ref="oval:org.mitre.oval:tst:34258"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33693"/>
            <criterion comment="fetchmail is earlier than 0:6.2.0-3.el3.4" test_ref="oval:org.mitre.oval:tst:34132"/>
            <criterion comment="mutt is earlier than 5:1.4.1-5.el3" test_ref="oval:org.mitre.oval:tst:34296"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34313"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34228"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34281"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33894"/>
            <criterion comment="evolution-devel is earlier than 0:1.4.5-20.el3" test_ref="oval:org.mitre.oval:tst:33933"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34334"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38549"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34366"/>
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:33625"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38591"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38694"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33931"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38715"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.1.el4" test_ref="oval:org.mitre.oval:tst:34331"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38864"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38837"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34021"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34249"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:34293"/>
            <criterion comment="evolution is earlier than 0:2.0.2-35.0.2.el4" test_ref="oval:org.mitre.oval:tst:34046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34446"/>
            <criterion comment="mutt is earlier than 5:1.4.1-12.0.3.el4" test_ref="oval:org.mitre.oval:tst:34260"/>
            <criterion comment="fetchmail is earlier than 0:6.2.5-6.0.1.el4" test_ref="oval:org.mitre.oval:tst:33955"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38523"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34262"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33994"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34322"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-35.0.2.el4" test_ref="oval:org.mitre.oval:tst:34116"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38178"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38751"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38045"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38362"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:33979"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38133"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38911"/>
            <criterion comment="evolution-data-server-devel is earlier than 0:1.8.0-15.0.3.el5" test_ref="oval:org.mitre.oval:tst:33399"/>
            <criterion comment="evolution-data-server is earlier than 0:1.8.0-15.0.3.el5" test_ref="oval:org.mitre.oval:tst:34181"/>
            <criterion comment="fetchmail is earlier than 0:6.3.6-1.0.1.el5" test_ref="oval:org.mitre.oval:tst:34122"/>
            <criterion comment="mutt is earlier than 5:1.4.2.2-3.0.2.el5" test_ref="oval:org.mitre.oval:tst:34241"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38738"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38762"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38574"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9781" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote attackers to cause a denial of service (abort) via the SNDCP dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1940" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1940"/>
        <description>Unspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote attackers to cause a denial of service (abort) via the SNDCP dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:46.501-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:03.782-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:10.189-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9781 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:08.739-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:08.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32590"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32299"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9780" version="5" class="vulnerability">
      <metadata>
        <title>The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1904"/>
        <description>The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:43.418-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:03.393-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:09.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9780 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:16.734-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:07.774-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38694"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38591"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38715"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38523"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38864"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38549"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38178"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38751"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38045"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38362"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38133"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38911"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38738"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38574"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38762"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:978" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Directory Traversal Vulnerabilities in LHA</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0235"/>
        <description>Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="lha version is less than 1.14i-10.2" negate="false" test_ref="oval:org.mitre.oval:tst:1370"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/lha is executable">
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1369"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1368"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1367"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9779" version="5" class="vulnerability">
      <metadata>
        <title>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:36.944-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:03.133-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:09.462-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9779 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:29.579-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:07.383-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.4" test_ref="oval:org.mitre.oval:tst:30638"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.4" test_ref="oval:org.mitre.oval:tst:30381"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.4" test_ref="oval:org.mitre.oval:tst:30673"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.42" test_ref="oval:org.mitre.oval:tst:32442"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="openssl096b is earlier than 0:0.9.6b-22.42" test_ref="oval:org.mitre.oval:tst:32297"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9778" version="5" class="vulnerability">
      <metadata>
        <title>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166"/>
        <description>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:26.782-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:02.500-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:08.764-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9778 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:52.541-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:06.554-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9777" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2269"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:26.747-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:01.957-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:08.263-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9777 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:13.283-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:05.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32142"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32131"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32154"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32001"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32171"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32162"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31782"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32041"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32004"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32120"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31633"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31837"/>
            <criterion comment="thunderbird is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32113"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32100"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31821"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31904"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31814"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31951"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31554"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32149"/>
            <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31998"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32061"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9776" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1667" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1667"/>
        <description>Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:33.447-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:00.716-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:07.360-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9776 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:22.930-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:04.731-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33447"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33884"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33550"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33984"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33936"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33976"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33799"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33867"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33958"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33791"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33929"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33764"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33070"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33716"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33788"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33928"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33930"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33951"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33950"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33932"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33656"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33963"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33466"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33846"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33660"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33687"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33689"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33499"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33719"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33696"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33811"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33258"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33567"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33738"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33938"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33663"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33066"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33875"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33789"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33829"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33434"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33704"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33790"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33886"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33982"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33715"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33856"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33815"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libX11-devel is earlier than 0:1.0.3-8.0.1.el5" test_ref="oval:org.mitre.oval:tst:33685"/>
            <criterion comment="libX11 is earlier than 0:1.0.3-8.0.1.el5" test_ref="oval:org.mitre.oval:tst:33774"/>
            <criterion comment="xorg-x11-apps is earlier than 0:7.1-4.0.1.el5" test_ref="oval:org.mitre.oval:tst:33082"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9775" version="5" class="vulnerability">
      <metadata>
        <title>The Unidirectional Lightweight Encapsulation (ULE) decapsulation component in dvb-core/dvb_net.c in the dvb driver in the Linux kernel 2.6.17.8 allows remote attackers to cause a denial of service (crash) via an SNDU length of 0 in a ULE packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4623" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4623"/>
        <description>The Unidirectional Lightweight Encapsulation (ULE) decapsulation component in dvb-core/dvb_net.c in the dvb driver in the Linux kernel 2.6.17.8 allows remote attackers to cause a denial of service (crash) via an SNDU length of 0 in a ULE packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:11.650-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:00.430-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:06.963-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9775 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:37.386-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:03.848-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32678"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32900"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33014"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32947"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32944"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32956"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32602"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33081"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32892"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9774" version="5" class="vulnerability">
      <metadata>
        <title>The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2874"/>
        <description>The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:32.581-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:00.224-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:06.740-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9774 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:45.009-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:03.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.8" test_ref="oval:org.mitre.oval:tst:31989"/>
          <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.8" test_ref="oval:org.mitre.oval:tst:31269"/>
          <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.8" test_ref="oval:org.mitre.oval:tst:31920"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9773" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0619" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0619"/>
        <description>Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:03.655-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:59.908-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:06.446-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9773 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:12.790-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:03.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30934"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30708"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30577"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30874"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30794"/>
          <criterion comment="kernel is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30892"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30873"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:31080"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30866"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9772" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6112"/>
        <description>Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:53.239-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:59.620-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:06.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9772 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:18.357-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:02.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9771" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3798"/>
        <description>Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:02.322-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:59.337-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:05.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9771 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:12.545-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:02.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-12.el4" test_ref="oval:org.mitre.oval:tst:34426"/>
            <criterion comment="libpcap is earlier than 14:0.8.3-12.el4" test_ref="oval:org.mitre.oval:tst:34317"/>
            <criterion comment="tcpdump is earlier than 14:3.8.2-12.el4" test_ref="oval:org.mitre.oval:tst:33439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-18.el5" test_ref="oval:org.mitre.oval:tst:34286"/>
            <criterion comment="libpcap-devel is earlier than 14:0.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:34191"/>
            <criterion comment="libpcap is earlier than 14:0.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:34045"/>
            <criterion comment="tcpdump is earlier than 14:3.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:33937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9770" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0504"/>
        <description>Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:08.343-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:58.859-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:05.343-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9770 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:31.525-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:01.502-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36201"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36534"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36373"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36702"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36615"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36490"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36370"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35738"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36249"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36731"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35733"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:977" version="1" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in LHA get_header Function</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0234"/>
        <description>Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="lha version is less than 1.14i-10.2" negate="false" test_ref="oval:org.mitre.oval:tst:1370"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/lha is executable">
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1369"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1368"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1367"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9769" version="5" class="vulnerability">
      <metadata>
        <title>Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0504"/>
        <description>Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:23.486-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:58.610-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:05.136-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9769 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:40.217-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:01.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ethereal-gnome is earlier than 0:0.10.3-0.30E.2" test_ref="oval:org.mitre.oval:tst:30484"/>
          <criterion comment="ethereal is earlier than 0:0.10.3-0.30E.2" test_ref="oval:org.mitre.oval:tst:30678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9768" version="5" class="vulnerability">
      <metadata>
        <title>The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs.  NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2784"/>
        <description>The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs.  NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:05.382-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:57.991-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:04.586-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9768 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:42.335-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:00.550-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9767" version="5" class="vulnerability">
      <metadata>
        <title>FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1807"/>
        <description>FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:05.197-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:57.656-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:04.237-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9767 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:35.880-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:00.010-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-10.el3" test_ref="oval:org.mitre.oval:tst:36608"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-10.el3" test_ref="oval:org.mitre.oval:tst:36928"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:36978"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:37295"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:36877"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:37292"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37321"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37312"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37160"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9766" version="5" class="vulnerability">
      <metadata>
        <title>The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current-clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2848"/>
        <description>The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:30.668-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:56.967-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:03.458-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9766 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:29.189-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:58.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39101"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39357"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38568"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39331"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39316"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39054"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39274"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39407"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39435"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39442"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38473"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38255"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38332"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39122"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39058"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39247"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39145"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38795"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38831"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38585"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39130"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38567"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39245"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9765" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5456"/>
        <description>Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:25.674-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:56.647-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:03.132-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9765 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:32.791-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:58.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33189"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33318"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33102"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33080"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33315"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33269"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33326"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:32926"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:32622"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9764" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2379"/>
        <description>Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:46.986-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:56.387-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:02.813-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9764 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:30.413-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:58.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-8.el3" test_ref="oval:org.mitre.oval:tst:38111"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.2" test_ref="oval:org.mitre.oval:tst:37956"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.2" test_ref="oval:org.mitre.oval:tst:37617"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9763" version="5" class="vulnerability">
      <metadata>
        <title>The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3511"/>
        <description>The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:36.301-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:55.813-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:02.280-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9763 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:27.518-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:57.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35512"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35540"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35394"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35541"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35553"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35552"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:34924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35155"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35489"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35324"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" test_ref="oval:org.mitre.oval:tst:35240"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35182"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35311"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35454"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.7.el4" test_ref="oval:org.mitre.oval:tst:35398"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35351"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35482"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34790"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35291"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35262"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35202"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-5.el5" test_ref="oval:org.mitre.oval:tst:35177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9762" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested option tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2779"/>
        <description>Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested &lt;option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:18.092-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:55.326-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:01.673-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9762 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:45.580-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:56.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9761" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules.  NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2315" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2315"/>
        <description>Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules.  NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:07.718-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:54.865-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:01.270-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9761 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:14.460-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:56.073-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38704"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38695"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38872"/>
            <criterion comment="python is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38617"/>
            <criterion comment="python-docs is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:37965"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38916"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38703"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38787"/>
            <criterion comment="python is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38939"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38889"/>
            <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38958"/>
            <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38827"/>
            <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9760" version="5" class="vulnerability">
      <metadata>
        <title>Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3191"/>
        <description>Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:01.428-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:54.378-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:00.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9760 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:00.098-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:55.400-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.34" test_ref="oval:org.mitre.oval:tst:32490"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.34" test_ref="oval:org.mitre.oval:tst:32463"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.34" test_ref="oval:org.mitre.oval:tst:31538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.9" test_ref="oval:org.mitre.oval:tst:31551"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.3" test_ref="oval:org.mitre.oval:tst:32230"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.9" test_ref="oval:org.mitre.oval:tst:32368"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.9" test_ref="oval:org.mitre.oval:tst:32431"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:976" version="1" class="vulnerability">
      <metadata>
        <title>tcpdump Identification Payload in ISAKMP Packets Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0184"/>
        <description>Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.2" negate="false" test_ref="oval:org.mitre.oval:tst:1374"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1373"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1372"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1371"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9759" version="5" class="vulnerability">
      <metadata>
        <title>The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0731"/>
        <description>The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:21.585-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:54.175-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:00.516-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9759 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:00.174-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:55.098-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gnutls is earlier than 0:1.0.20-4.el4_8.7" test_ref="oval:org.mitre.oval:tst:39971"/>
          <criterion comment="gnutls-devel is earlier than 0:1.0.20-4.el4_8.7" test_ref="oval:org.mitre.oval:tst:40233"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9758" version="5" class="vulnerability">
      <metadata>
        <title>smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0452" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0452"/>
        <description>smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:19.184-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:53.784-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:00.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9758 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:22.985-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:54.520-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.12" test_ref="oval:org.mitre.oval:tst:33498"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.12" test_ref="oval:org.mitre.oval:tst:32942"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.12" test_ref="oval:org.mitre.oval:tst:33319"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.12" test_ref="oval:org.mitre.oval:tst:33433"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.10-1.4E.11" test_ref="oval:org.mitre.oval:tst:32739"/>
            <criterion comment="samba-swat is earlier than 0:3.0.10-1.4E.11" test_ref="oval:org.mitre.oval:tst:33281"/>
            <criterion comment="samba-client is earlier than 0:3.0.10-1.4E.11" test_ref="oval:org.mitre.oval:tst:33449"/>
            <criterion comment="samba is earlier than 0:3.0.10-1.4E.11" test_ref="oval:org.mitre.oval:tst:33469"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.23c-2.el5.2" test_ref="oval:org.mitre.oval:tst:33413"/>
            <criterion comment="samba-swat is earlier than 0:3.0.23c-2.el5.2" test_ref="oval:org.mitre.oval:tst:33148"/>
            <criterion comment="samba-client is earlier than 0:3.0.23c-2.el5.2" test_ref="oval:org.mitre.oval:tst:33443"/>
            <criterion comment="samba is earlier than 0:3.0.23c-2.el5.2" test_ref="oval:org.mitre.oval:tst:33362"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9757" version="5" class="vulnerability">
      <metadata>
        <title>NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3286"/>
        <description>NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:02.115-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:53.470-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:59.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9757 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:22.846-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:54.084-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39665"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39142"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39538"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39699"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39518"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39350"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39738"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39663"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39536"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39189"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39141"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9756" version="5" class="vulnerability">
      <metadata>
        <title>CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4624"/>
        <description>CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:45.170-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:53.293-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:59.515-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9756 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:25.598-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:53.750-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="mailman is earlier than 3:2.1.5.1-34.rhel4.6" test_ref="oval:org.mitre.oval:tst:34946"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9755" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3114"/>
        <description>Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:21.914-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:52.840-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:59.098-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37481"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36778"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37475"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37445"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37487"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37483"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36649"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37229"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37509"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37426"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37368"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37035"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37181"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37441"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37315"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37359"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37490"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37461"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9754" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1678"/>
        <description>Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:47.822-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:52.623-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:58.827-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9754 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:47:06.484-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:53.124-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.1" test_ref="oval:org.mitre.oval:tst:38708"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.1" test_ref="oval:org.mitre.oval:tst:38006"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.1" test_ref="oval:org.mitre.oval:tst:38104"/>
          <criterion comment="httpd is earlier than 0:2.2.3-22.el5_3.1" test_ref="oval:org.mitre.oval:tst:38358"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9753" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows scripts with the UniversalBrowserRead privilege to gain UniversalXPConnect privileges and possibly execute code or obtain sensitive data by reading into a privileged context.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3809"/>
        <description>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows scripts with the UniversalBrowserRead privilege to gain UniversalXPConnect privileges and possibly execute code or obtain sensitive data by reading into a privileged context.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:19.804-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:52.136-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:58.334-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9753 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:41.076-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:52.444-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9752" version="5" class="vulnerability">
      <metadata>
        <title>Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0976" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0976"/>
        <description>Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:20.928-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:51.854-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:58.088-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9752 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:08.292-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:52.119-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="perl-suidperl is earlier than 2:5.8.0-90.4" test_ref="oval:org.mitre.oval:tst:32422"/>
          <criterion comment="perl is earlier than 2:5.8.0-90.4" test_ref="oval:org.mitre.oval:tst:32487"/>
          <criterion comment="perl-CPAN is earlier than 2:1.61-90.4" test_ref="oval:org.mitre.oval:tst:32255"/>
          <criterion comment="perl-CGI is earlier than 2:2.89-90.4" test_ref="oval:org.mitre.oval:tst:32543"/>
          <criterion comment="perl-DB_File is earlier than 2:1.806-90.4" test_ref="oval:org.mitre.oval:tst:32488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9751" version="5" class="vulnerability">
      <metadata>
        <title>The binfmt functionality in the Linux kernel, when "memory overcommit" is enabled, allows local users to cause a denial of service (kernel oops) via a malformed a.out binary.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1074"/>
        <description>The binfmt functionality in the Linux kernel, when "memory overcommit" is enabled, allows local users to cause a denial of service (kernel oops) via a malformed a.out binary.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:21.515-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:51.578-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:57.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9751 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:37.399-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:51.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31090"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31317"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31165"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31297"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31259"/>
          <criterion comment="kernel is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:30906"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31029"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31014"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:30920"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9750" version="5" class="vulnerability">
      <metadata>
        <title>wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1488"/>
        <description>wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:41.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:51.361-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:57.506-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9750 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:05.438-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:51.364-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-1.30E.1" test_ref="oval:org.mitre.oval:tst:31680"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-2.4E.1" test_ref="oval:org.mitre.oval:tst:31717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:975" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL do_change_cipher_spec Function Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.326-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:11.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9749" version="5" class="vulnerability">
      <metadata>
        <title>A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0994" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0994"/>
        <description>A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:21.470-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:50.758-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:56.896-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9749 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:24.543-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:50.545-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9748" version="5" class="vulnerability">
      <metadata>
        <title>The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3276" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3276"/>
        <description>The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:10.717-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:50.364-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:56.491-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9748 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:29.513-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:49.951-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32345"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32444"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32109"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32476"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32343"/>
            <criterion comment="kernel is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:31877"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32362"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32190"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:31899"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9747" version="5" class="vulnerability">
      <metadata>
        <title>Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0109"/>
        <description>Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:12.987-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:50.003-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:56.183-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9747 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:53:01.374-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:49.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.17" test_ref="oval:org.mitre.oval:tst:32376"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.17" test_ref="oval:org.mitre.oval:tst:32370"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.17" test_ref="oval:org.mitre.oval:tst:32357"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.22.4" test_ref="oval:org.mitre.oval:tst:32193"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.4" test_ref="oval:org.mitre.oval:tst:31576"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.4" test_ref="oval:org.mitre.oval:tst:31826"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.4" test_ref="oval:org.mitre.oval:tst:32196"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-22.4" test_ref="oval:org.mitre.oval:tst:32241"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9746" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6501" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6501"/>
        <description>Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:14.895-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:49.515-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:55.625-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9746 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:06.247-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:48.711-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32785"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33227"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33266"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33146"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32352"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33183"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33095"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32996"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33195"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33229"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33273"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33259"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33239"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33284"/>
            <criterion comment="firefox is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32815"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33153"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33015"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33251"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33336"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32408"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9745" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0908" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0908"/>
        <description>Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:59.722-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:49.223-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:55.319-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9745 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:51:48.780-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:48.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:30915"/>
          <criterion comment="mozilla is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:30964"/>
          <criterion comment="mozilla-chat is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:30905"/>
          <criterion comment="mozilla-mail is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:30635"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:31000"/>
          <criterion comment="mozilla-devel is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:30111"/>
          <criterion comment="mozilla-nss is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:30762"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:31048"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:30856"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.4" test_ref="oval:org.mitre.oval:tst:30834"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9744" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1379"/>
        <description>Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:59.468-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:48.972-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:55.095-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9744 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:53.390-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:47.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5" test_ref="oval:org.mitre.oval:tst:39059"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5" test_ref="oval:org.mitre.oval:tst:38295"/>
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5" test_ref="oval:org.mitre.oval:tst:38660"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9743" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1183"/>
        <description>Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:57.439-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:48.723-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:54.788-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9743 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:01.351-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:47.616-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-22.el3" test_ref="oval:org.mitre.oval:tst:31219"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-22.el3" test_ref="oval:org.mitre.oval:tst:30876"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-8" test_ref="oval:org.mitre.oval:tst:31174"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-8" test_ref="oval:org.mitre.oval:tst:30884"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9742" version="5" class="vulnerability">
      <metadata>
        <title>Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0733"/>
        <description>Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:58.476-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:48.456-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:54.508-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9742 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:15.253-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:47.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="python-lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" test_ref="oval:org.mitre.oval:tst:38555"/>
          <criterion comment="lcms-devel is earlier than 0:1.18-0.1.beta1.el5_3.2" test_ref="oval:org.mitre.oval:tst:37972"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:38276"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:37661"/>
          <criterion comment="lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" test_ref="oval:org.mitre.oval:tst:38260"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:37652"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:37769"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:38561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9741" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2027"/>
        <description>Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:41.854-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:48.236-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:54.271-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9741 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:45.868-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:46.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="elinks is earlier than 0:0.9.2-4.el4_8.1" test_ref="oval:org.mitre.oval:tst:39356"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="elinks is earlier than 0:0.11.1-6.el5_4.1" test_ref="oval:org.mitre.oval:tst:39490"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9740" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that tragger an assertion error related to unexpected length values.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4574"/>
        <description>Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that tragger an assertion error related to unexpected length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:03.865-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:47.739-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:53.974-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9740 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:49.858-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:46.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33205"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33170"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:32550"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:33152"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9739" version="5" class="vulnerability">
      <metadata>
        <title>PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0555"/>
        <description>PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:22.918-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:47.130-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:52.923-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9739 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:48.712-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:45.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33558"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33220"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33285"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33432"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33464"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33104"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33317"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33537"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33539"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33243"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33246"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33442"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33531"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33065"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32982"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33144"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33007"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33534"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33427"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33173"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33069"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33496"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33181"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33488"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33593"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33121"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33568"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33396"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33603"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:32610"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:32997"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33536"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9738" version="5" class="vulnerability">
      <metadata>
        <title>A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3556" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3556"/>
        <description>A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:25.665-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:46.778-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:52.590-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9738 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:41.314-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:45.148-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40050"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39464"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39090"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40063"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39443"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39703"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39080"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39862"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40057"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40029"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39849"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40039"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9737" version="5" class="vulnerability">
      <metadata>
        <title>KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0164" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0164"/>
        <description>KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:26.406-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:46.573-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:52.396-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9737 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:51:39.224-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:44.817-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="ipsec-tools is earlier than 0:0.2.5-0.4" test_ref="oval:org.mitre.oval:tst:30611"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9736" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows remote attackers to execute arbitrary code via a crafted SGI image file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0762"/>
        <description>Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows remote attackers to execute arbitrary code via a crafted SGI image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:30.604-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:46.345-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:52.156-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9736 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:26.567-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:44.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30471"/>
          <criterion comment="ImageMagick is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30355"/>
          <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30877"/>
          <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30918"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30938"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9735" version="5" class="vulnerability">
      <metadata>
        <title>The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4573"/>
        <description>The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:46.151-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:45.691-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:51.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9735 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:32.084-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:43.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:34612"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35360"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35290"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35242"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35278"/>
            <criterion comment="kernel is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35340"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:34986"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35236"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35318"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35329"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35328"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35371"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35052"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:34704"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35333"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35379"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:34761"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35277"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35265"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35040"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35220"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35380"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:34544"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35347"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35287"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:34472"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35307"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:34914"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35213"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:34797"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35297"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9734" version="5" class="vulnerability">
      <metadata>
        <title>The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3726"/>
        <description>The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:40.562-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:45.206-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:50.917-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9734 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:23.267-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:42.954-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40810"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40798"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40737"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40705"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40784"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40711"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40801"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40491"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40523"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40665"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40648"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39674"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39635"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39630"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39766"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39742"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39295"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:38900"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39772"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39784"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39625"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39731"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9733" version="5" class="vulnerability">
      <metadata>
        <title>The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0888" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0888"/>
        <description>The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:22.441-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:44.963-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:50.720-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9733 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:53:10.955-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:42.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="unzip is earlier than 0:5.50-36.EL3" test_ref="oval:org.mitre.oval:tst:36585"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9732" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0744" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0744"/>
        <description>Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:20.574-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:44.552-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:50.295-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9732 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:51:43.565-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:42.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32158"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32589"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32704"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32562"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32078"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32513"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32231"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32097"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32708"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
            <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9731" version="3" class="vulnerability">
      <metadata>
        <title>The DOC.print function in the Adobe JavaScript API, as used by Adobe Acrobat and Reader before 8.1.2, allows remote attackers to configure silent non-interactive printing, and trigger the printing of an arbitrary number of copies of a document.  NOTE: this issue might be subsumed by CVE-2008-0655.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0667" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0667"/>
        <description>The DOC.print function in the Adobe JavaScript API, as used by Adobe Acrobat and Reader before 8.1.2, allows remote attackers to configure silent non-interactive printing, and trigger the printing of an arbitrary number of copies of a document.  NOTE: this issue might be subsumed by CVE-2008-0655.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:47.374-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:44.267-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:49.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:8.1.2-1.el3.6" test_ref="oval:org.mitre.oval:tst:36324"/>
            <criterion comment="acroread is earlier than 0:8.1.2-1.el3.6" test_ref="oval:org.mitre.oval:tst:36153"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:8.1.2-1.el4.2" test_ref="oval:org.mitre.oval:tst:36156"/>
            <criterion comment="acroread is earlier than 0:8.1.2-1.el4.2" test_ref="oval:org.mitre.oval:tst:36293"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:8.1.2-1.el5.3" test_ref="oval:org.mitre.oval:tst:35792"/>
            <criterion comment="acroread is earlier than 0:8.1.2-1.el5.3" test_ref="oval:org.mitre.oval:tst:35912"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9730" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0981"/>
        <description>Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:27.304-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:43.616-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:49.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9730 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:38.157-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:41.312-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9729" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6736"/>
        <description>Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:31.770-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:43.187-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:48.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criteria operator="OR">
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33298"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33521"/>
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33376"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33428"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33515"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33417"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:32803"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33585"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33064"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33481"/>
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33563"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33479"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33472"/>
            <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:32903"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33667"/>
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33199"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33754"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33366"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33073"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33547"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9728" version="5" class="vulnerability">
      <metadata>
        <title>The GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via a GIF image that has no global color map.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3475" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3475"/>
        <description>The GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via a GIF image that has no global color map.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:04.145-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:42.867-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:48.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9728 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:46.340-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:40.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36386"/>
            <criterion comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36408"/>
            <criterion comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:35731"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36297"/>
            <criterion comment="gd-devel is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36448"/>
            <criterion comment="gd-progs is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35759"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9727" version="5" class="vulnerability">
      <metadata>
        <title>The time_out_leases function in locks.c for Linux kernel before 2.6.15-rc3 allows local users to cause a denial of service (kernel log message consumption) by causing a large number of broken leases, which is recorded to the log using the printk function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3857"/>
        <description>The time_out_leases function in locks.c for Linux kernel before 2.6.15-rc3 allows local users to cause a denial of service (kernel log message consumption) by causing a large number of broken leases, which is recorded to the log using the printk function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:13.802-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:42.478-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:48.199-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9727 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:01.558-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:40.320-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9726" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99.5 to 0.99.6, when running on unspecified platforms, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6115" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6115"/>
        <description>Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99.5 to 0.99.6, when running on unspecified platforms, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:43.583-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:42.112-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:47.777-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9726 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:35.429-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:39.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9725" version="5" class="vulnerability">
      <metadata>
        <title>Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1659" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1659"/>
        <description>Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:22.361-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:41.834-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:47.524-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9725 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:28.461-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:39.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:4.5-4.el4_6.6" test_ref="oval:org.mitre.oval:tst:35615"/>
            <criterion comment="pcre is earlier than 0:4.5-4.el4_6.6" test_ref="oval:org.mitre.oval:tst:35501"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:6.6-2.el5_0.1" test_ref="oval:org.mitre.oval:tst:35420"/>
            <criterion comment="pcre is earlier than 0:6.6-2.el5_0.1" test_ref="oval:org.mitre.oval:tst:35187"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9724" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3658"/>
        <description>Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:05.665-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:41.136-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:46.762-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9724 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:46.798-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:38.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:38010"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37683"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37468"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37994"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37569"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37746"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38324"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38288"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38029"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:37974"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38154"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38499"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38401"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38018"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38505"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38494"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38075"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38387"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38058"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38147"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38305"/>
            <criterion comment="php-common is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38268"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38298"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37882"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37952"/>
            <criterion comment="php is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38099"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38415"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38511"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38115"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38367"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38569"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38440"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38536"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38507"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38316"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38493"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37667"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9723" version="6" class="vulnerability">
      <metadata>
        <title>The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstated by the (1) /admin?OP=redirectURL=% and (2) /admin?URL=/admin/OP=% URIs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1748"/>
        <description>The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&amp;URL=% and (2) /admin?URL=/admin/&amp;OP=% URIs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:34.305-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:40.724-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:46.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9723 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:55.637-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:37.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.65" test_ref="oval:org.mitre.oval:tst:40547"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.65" test_ref="oval:org.mitre.oval:tst:40758"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.65" test_ref="oval:org.mitre.oval:tst:40348"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.32.el4_8.6" test_ref="oval:org.mitre.oval:tst:40606"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.32.el4_8.6" test_ref="oval:org.mitre.oval:tst:40609"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.32.el4_8.6" test_ref="oval:org.mitre.oval:tst:40697"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:40805"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:40819"/>
            <criterion comment="cups is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:40803"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:40393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9722" version="5" class="vulnerability">
      <metadata>
        <title>Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0909" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0909"/>
        <description>Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:01.285-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:39.971-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:45.626-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9722 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:20.800-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:36.622-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9721" version="5" class="vulnerability">
      <metadata>
        <title>The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0635" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0635"/>
        <description>The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:44.142-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:39.766-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:45.419-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9721 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:42.487-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:36.335-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ethereal-gnome is earlier than 0:0.10.5-0.30E.2" test_ref="oval:org.mitre.oval:tst:29799"/>
          <criterion comment="ethereal is earlier than 0:0.10.5-0.30E.2" test_ref="oval:org.mitre.oval:tst:30522"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9720" version="5" class="vulnerability">
      <metadata>
        <title>The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0442"/>
        <description>The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:29.228-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:39.164-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:44.765-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9720 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:59.782-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:35.507-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40180"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40440"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40426"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40220"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:39618"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40140"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40502"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:39925"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40137"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40551"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40486"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40521"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40292"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40516"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40066"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40399"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40512"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40314"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40428"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40366"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40465"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40401"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40402"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40538"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:39839"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40515"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40505"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40251"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40253"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40509"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40309"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:972" version="1" class="vulnerability">
      <metadata>
        <title>tcpdump Delete Payload in ISAKMP Packets Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0183"/>
        <description>TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.2" negate="false" test_ref="oval:org.mitre.oval:tst:1374"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1373"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1372"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1371"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9719" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-7234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7234"/>
        <description>Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:11.863-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:38.830-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:44.499-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9719 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:48.421-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:34.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-11.3" test_ref="oval:org.mitre.oval:tst:37424"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-18.2.el4_7.1" test_ref="oval:org.mitre.oval:tst:37925"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-28.1.el5_2.1" test_ref="oval:org.mitre.oval:tst:37898"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9718" version="5" class="vulnerability">
      <metadata>
        <title>Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0829"/>
        <description>Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:03.523-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:38.572-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:44.233-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9718 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:17.140-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:34.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
          <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
          <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
          <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
          <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
          <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
          <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9717" version="5" class="vulnerability">
      <metadata>
        <title>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2798"/>
        <description>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:54.951-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:38.343-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:43.943-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9717 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:48.765-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:34.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="openssh is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:31991"/>
          <criterion comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:31339"/>
          <criterion comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:31258"/>
          <criterion comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:32054"/>
          <criterion comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:31494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9716" version="5" class="vulnerability">
      <metadata>
        <title>agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-4309.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1887" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1887"/>
        <description>agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-4309.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:17.666-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:38.104-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:43.698-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9716 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:24.480-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:33.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.28" test_ref="oval:org.mitre.oval:tst:38756"/>
          <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.28" test_ref="oval:org.mitre.oval:tst:38263"/>
          <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.28" test_ref="oval:org.mitre.oval:tst:38869"/>
          <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.28" test_ref="oval:org.mitre.oval:tst:38866"/>
          <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.28" test_ref="oval:org.mitre.oval:tst:38753"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9715" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1437" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1437"/>
        <description>Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:31.740-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:37.468-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:43.062-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9715 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:01.969-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:33.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40810"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40798"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40737"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40705"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40784"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40711"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40801"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40491"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40523"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40665"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40648"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40501"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40283"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40807"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40842"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40793"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40732"/>
            <criterion comment="kernel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40830"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40349"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39978"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39896"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40791"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9714" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0888" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0888"/>
        <description>Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:38.808-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:37.126-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:42.676-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9714 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:10.645-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:32.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31559"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31693"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31615"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.16" test_ref="oval:org.mitre.oval:tst:30852"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31603"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.16" test_ref="oval:org.mitre.oval:tst:31062"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31685"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.3" test_ref="oval:org.mitre.oval:tst:31089"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31747"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.16" test_ref="oval:org.mitre.oval:tst:30949"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:31263"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:31323"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9713" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1462"/>
        <description>Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:39.744-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:36.823-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:42.423-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9713 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:19.469-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:32.415-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9712" version="5" class="vulnerability">
      <metadata>
        <title>Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2929" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2929"/>
        <description>Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:17.736-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:36.606-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:42.195-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9712 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:50.785-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:32.013-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-11.2" test_ref="oval:org.mitre.oval:tst:32358"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-18.2" test_ref="oval:org.mitre.oval:tst:32237"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9711" version="5" class="vulnerability">
      <metadata>
        <title>Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2479" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2479"/>
        <description>Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:33.643-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:36.391-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:41.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9711 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:52.444-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:31.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.14" test_ref="oval:org.mitre.oval:tst:32129"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.11" test_ref="oval:org.mitre.oval:tst:32053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9710" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0891"/>
        <description>Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:45.459-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:36.080-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:41.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9710 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:26.457-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:31.220-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-12.el3" test_ref="oval:org.mitre.oval:tst:31425"/>
            <criterion comment="gtk2 is earlier than 0:2.2.4-15" test_ref="oval:org.mitre.oval:tst:31683"/>
            <criterion comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-12.el3" test_ref="oval:org.mitre.oval:tst:31384"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-12.el3" test_ref="oval:org.mitre.oval:tst:31449"/>
            <criterion comment="gtk2-devel is earlier than 0:2.2.4-15" test_ref="oval:org.mitre.oval:tst:31230"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-16.el4" test_ref="oval:org.mitre.oval:tst:31640"/>
            <criterion comment="gtk2 is earlier than 0:2.4.13-14" test_ref="oval:org.mitre.oval:tst:31176"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-16.el4" test_ref="oval:org.mitre.oval:tst:31509"/>
            <criterion comment="gtk2-devel is earlier than 0:2.4.13-14" test_ref="oval:org.mitre.oval:tst:31725"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:971" version="2" class="vulnerability">
      <metadata>
        <title>libpng Malformed PNG Image Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0421"/>
        <description>The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:34.590-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:11.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="libpng/libpng-devel is less than 1.2.2-21 or libpng10/libpng-devel less than 1.0.13 is installed">
          <criterion comment="libpng version is less than 1.2.2-21" negate="false" test_ref="oval:org.mitre.oval:tst:1378"/>
          <criterion comment="libpng-devel version is less than 1.2.2-21" negate="false" test_ref="oval:org.mitre.oval:tst:1377"/>
          <criterion comment="libpng10 version is less than 1.0.13-12" negate="false" test_ref="oval:org.mitre.oval:tst:1376"/>
          <criterion comment="libpng10-devel version is less than 1.0.13-12" negate="false" test_ref="oval:org.mitre.oval:tst:1375"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9709" version="5" class="vulnerability">
      <metadata>
        <title>VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0001"/>
        <description>VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:01.857-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:35.534-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:41.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9709 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:32.989-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:30.531-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36030"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35766"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36138"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36062"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35611"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35990"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35969"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36085"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36026"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36084"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36097"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36035"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35648"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9708" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0469"/>
        <description>Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:10.721-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:35.173-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:40.689-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9708 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:27.634-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:29.965-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31573"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31050"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31373"/>
            <criterion comment="telnet is earlier than 1:0.17-26.EL3.2" test_ref="oval:org.mitre.oval:tst:31054"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31472"/>
            <criterion comment="telnet-server is earlier than 1:0.17-26.EL3.2" test_ref="oval:org.mitre.oval:tst:31463"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31015"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31409"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:30952"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31575"/>
            <criterion comment="telnet is earlier than 1:0.17-31.EL4.2" test_ref="oval:org.mitre.oval:tst:31498"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31481"/>
            <criterion comment="telnet-server is earlier than 1:0.17-31.EL4.2" test_ref="oval:org.mitre.oval:tst:31275"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31526"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9707" version="5" class="vulnerability">
      <metadata>
        <title>Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to cause a denial of service.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0986"/>
        <description>Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:58.326-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:34.853-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:40.400-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9707 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:47.733-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:29.602-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-9.EL" test_ref="oval:org.mitre.oval:tst:30492"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-9.EL" test_ref="oval:org.mitre.oval:tst:30319"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-9.EL" test_ref="oval:org.mitre.oval:tst:30091"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-9.EL" test_ref="oval:org.mitre.oval:tst:30430"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-9.EL" test_ref="oval:org.mitre.oval:tst:30603"/>
          <criterion comment="kernel is earlier than 0:2.4.21-9.EL" test_ref="oval:org.mitre.oval:tst:30486"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-9.EL" test_ref="oval:org.mitre.oval:tst:30341"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-9.EL" test_ref="oval:org.mitre.oval:tst:30477"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-9.EL" test_ref="oval:org.mitre.oval:tst:30442"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9706" version="5" class="vulnerability">
      <metadata>
        <title>Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0928" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0928"/>
        <description>Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:30.294-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:34.648-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:40.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9706 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:10.436-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:29.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="xen-libs is earlier than 0:3.0.3-41.el5_1.5" test_ref="oval:org.mitre.oval:tst:36530"/>
          <criterion comment="xen is earlier than 0:3.0.3-41.el5_1.5" test_ref="oval:org.mitre.oval:tst:36543"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-41.el5_1.5" test_ref="oval:org.mitre.oval:tst:35758"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9705" version="5" class="vulnerability">
      <metadata>
        <title>sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5495"/>
        <description>sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:20.428-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:34.444-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:39.912-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9705 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:21.613-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:28.948-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="setroubleshoot-plugins is earlier than 0:2.0.4-2.el5" test_ref="oval:org.mitre.oval:tst:35813"/>
          <criterion comment="setroubleshoot-server is earlier than 0:2.0.5-3.el5" test_ref="oval:org.mitre.oval:tst:36096"/>
          <criterion comment="setroubleshoot is earlier than 0:2.0.5-3.el5" test_ref="oval:org.mitre.oval:tst:35777"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9704" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3117"/>
        <description>Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:37.580-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:34.169-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:39.624-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9704 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:56.365-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:27.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32211"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32773"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31834"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32763"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32657"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32835"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32791"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9703" version="5" class="vulnerability">
      <metadata>
        <title>The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2778"/>
        <description>The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:36.150-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:33.618-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:39.127-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9703 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:20.812-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:27.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9702" version="5" class="vulnerability">
      <metadata>
        <title>drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4538"/>
        <description>drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:21.466-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:33.137-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:38.577-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9702 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:11.436-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:26.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39702"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39797"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39763"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39709"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39503"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39617"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39773"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39516"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39093"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39662"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39657"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39645"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39650"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39813"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39095"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39770"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39099"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39700"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39408"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39590"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39719"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39789"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:38905"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9700" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1456"/>
        <description>Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:54.326-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:32.619-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:38.068-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9700 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:40.455-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:26.252-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:970" version="2" class="vulnerability">
      <metadata>
        <title>CVS pserver BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0396"/>
        <description>Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:47.770-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:11.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-22" negate="false" test_ref="oval:org.mitre.oval:tst:1382"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:97" version="4" class="vulnerability">
      <metadata>
        <title>Solaris cachefsd Buffer Overrun Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0084"/>
        <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Updated to add patch test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2005-01-28T12:00:00.000-04:00" comment="Added Solaris 9 and Solaris 9 patch test to the definition">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-01T08:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.350-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:45.666-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:11.147-04:00">ACCEPTED</status_change>
            <modified comment="Fixed incorrect user_id element value in process_state.  Incorrect value was 'root', updated to value of '0'." date="2010-09-02T15:11:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T15:13:54.266-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:47.360-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File cachefsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3053"/>
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 110896-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2946"/>
          <criterion comment="Patch 114008-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3050"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File cachefsd executable">
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3048"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3047"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9699" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to allows local users to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448.  It is different from CVE-2008-5302 due to affected versions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5303"/>
        <description>Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to allows local users to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448.  It is different from CVE-2008-5302 due to affected versions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:35.613-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:32.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:37.833-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9699 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:47:16.326-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:25.896-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="perl-suidperl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:40657"/>
          <criterion comment="perl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:39926"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9698" version="5" class="vulnerability">
      <metadata>
        <title>The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0108"/>
        <description>The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:26.007-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:32.240-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:37.642-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9698 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:38.440-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:25.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="sysstat is earlier than 0:4.0.7-4.EL3.2" test_ref="oval:org.mitre.oval:tst:30549"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9697" version="5" class="vulnerability">
      <metadata>
        <title>io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2975" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2975"/>
        <description>io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:48.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:31.892-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:37.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9697 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:28.518-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:25.202-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32203"/>
            <criterion comment="gtk2 is earlier than 0:2.2.4-19" test_ref="oval:org.mitre.oval:tst:32214"/>
            <criterion comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32393"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32388"/>
            <criterion comment="gtk2-devel is earlier than 0:2.2.4-19" test_ref="oval:org.mitre.oval:tst:32156"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32239"/>
            <criterion comment="gtk2 is earlier than 0:2.4.13-18" test_ref="oval:org.mitre.oval:tst:32313"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32331"/>
            <criterion comment="gtk2-devel is earlier than 0:2.4.13-18" test_ref="oval:org.mitre.oval:tst:32250"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9696" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1990"/>
        <description>Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:24.929-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:31.439-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:36.816-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9696 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:26.280-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:24.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32694"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32635"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32094"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32734"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32506"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32594"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32619"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32609"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:31938"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:31791"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32729"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32676"/>
            <criterion comment="php is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32607"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32412"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32084"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32271"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32269"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32783"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32718"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32732"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9695" version="5" class="vulnerability">
      <metadata>
        <title>The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0506" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0506"/>
        <description>The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:22.750-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:31.141-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:36.603-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9695 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:29.845-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:24.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ethereal-gnome is earlier than 0:0.10.3-0.30E.2" test_ref="oval:org.mitre.oval:tst:30484"/>
          <criterion comment="ethereal is earlier than 0:0.10.3-0.30E.2" test_ref="oval:org.mitre.oval:tst:30678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9694" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0586" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0586"/>
        <description>Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:47.874-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:30.882-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:36.399-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9694 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:23.741-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:23.981-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gstreamer-plugins-base-devel is earlier than 0:0.10.20-3.0.1.el5_3" test_ref="oval:org.mitre.oval:tst:37960"/>
          <criterion comment="gstreamer-plugins-base is earlier than 0:0.10.20-3.0.1.el5_3" test_ref="oval:org.mitre.oval:tst:38544"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9693" version="3" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0045"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:09.924-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:30.592-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:36.098-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criteria operator="OR">
            <criterion comment="acroread-libs-atk is earlier than 0:1.8.0-1.el3" test_ref="oval:org.mitre.oval:tst:32952"/>
            <criterion comment="acroread-plugin is earlier than 0:7.0.9-1.1.1.EL3" test_ref="oval:org.mitre.oval:tst:33372"/>
            <criterion comment="acroread-libs-glib2 is earlier than 0:2.4.7-1" test_ref="oval:org.mitre.oval:tst:33249"/>
            <criterion comment="acroread-libs-gtk2 is earlier than 0:2.4.13-1.el3" test_ref="oval:org.mitre.oval:tst:33161"/>
            <criterion comment="acroread-libs-pango is earlier than 0:1.6.0-1.el3" test_ref="oval:org.mitre.oval:tst:33353"/>
            <criterion comment="acroread-libs-gtk2-engines is earlier than 0:2.2.0-1.el3" test_ref="oval:org.mitre.oval:tst:32853"/>
            <criterion comment="acroread is earlier than 0:7.0.9-1.1.1.EL3" test_ref="oval:org.mitre.oval:tst:32959"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:7.0.9-1.2.0.EL4" test_ref="oval:org.mitre.oval:tst:33267"/>
            <criterion comment="acroread is earlier than 0:7.0.9-1.2.0.EL4" test_ref="oval:org.mitre.oval:tst:32938"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9692" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0925" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0925"/>
        <description>Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:19.414-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:30.394-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:35.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9692 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:17.751-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:23.703-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ethereal-gnome is earlier than 0:0.9.16-0.30E.1" test_ref="oval:org.mitre.oval:tst:30378"/>
          <criterion comment="ethereal is earlier than 0:0.9.16-0.30E.1" test_ref="oval:org.mitre.oval:tst:29663"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9691" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0927" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0927"/>
        <description>Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:09.998-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:30.198-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:35.581-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9691 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:08.788-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:23.427-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ethereal-gnome is earlier than 0:0.9.16-0.30E.1" test_ref="oval:org.mitre.oval:tst:30378"/>
          <criterion comment="ethereal is earlier than 0:0.9.16-0.30E.1" test_ref="oval:org.mitre.oval:tst:29663"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9690" version="5" class="vulnerability">
      <metadata>
        <title>Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3388"/>
        <description>Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:26.464-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:29.680-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:35.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9690 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:42.573-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:22.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34378"/>
            <criterion comment="qt is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34752"/>
            <criterion comment="qt-devel is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34863"/>
            <criterion comment="qt-MySQL is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34860"/>
            <criterion comment="qt-ODBC is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34610"/>
            <criterion comment="qt-designer is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34657"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34716"/>
            <criterion comment="qt is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34773"/>
            <criterion comment="qt-devel is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34824"/>
            <criterion comment="qt-PostgreSQL is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34273"/>
            <criterion comment="qt-MySQL is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34815"/>
            <criterion comment="qt-ODBC is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:33935"/>
            <criterion comment="qt-designer is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34901"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34546"/>
            <criterion comment="qt is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34540"/>
            <criterion comment="qt-MySQL is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34891"/>
            <criterion comment="qt-ODBC is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34751"/>
            <criterion comment="qt-designer is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34786"/>
            <criterion comment="qt-devel is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34503"/>
            <criterion comment="qt-PostgreSQL is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34497"/>
            <criterion comment="qt-devel-docs is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34823"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9689" version="5" class="vulnerability">
      <metadata>
        <title>login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-7108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7108"/>
        <description>login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:33.355-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:29.498-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:34.818-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9689 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:47.286-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:22.358-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="util-linux is earlier than 0:2.12a-16.EL4.25" test_ref="oval:org.mitre.oval:tst:34034"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9688" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0753"/>
        <description>Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:11.791-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:29.279-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:34.585-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9688 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:22.145-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:21.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cvs is earlier than 0:1.11.2-27" test_ref="oval:org.mitre.oval:tst:31763"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cvs is earlier than 0:1.11.17-7.RHEL4" test_ref="oval:org.mitre.oval:tst:31635"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9687" version="5" class="vulnerability">
      <metadata>
        <title>The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0739"/>
        <description>The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:59.277-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:28.974-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:34.333-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9687 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:24.517-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:21.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31514"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31448"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31593"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31548"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9686" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2654" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2654"/>
        <description>Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:12.365-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:28.445-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:33.753-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9686 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:11.611-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:20.773-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39378"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39359"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39036"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39270"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39397"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39118"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38466"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39389"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39088"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39081"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39351"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:38976"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el4" test_ref="oval:org.mitre.oval:tst:39195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39181"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39364"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39293"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39208"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39001"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39223"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39097"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39150"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39206"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9685" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the CIP dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger allocation of large amounts of memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6451"/>
        <description>Unspecified vulnerability in the CIP dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger allocation of large amounts of memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:39.866-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:28.073-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:33.379-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9685 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:17.088-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:20.220-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9684" version="3" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0046"/>
        <description>Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:54.379-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:27.741-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:32.947-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criteria operator="OR">
            <criterion comment="acroread-libs-atk is earlier than 0:1.8.0-1.el3" test_ref="oval:org.mitre.oval:tst:32952"/>
            <criterion comment="acroread-plugin is earlier than 0:7.0.9-1.1.1.EL3" test_ref="oval:org.mitre.oval:tst:33372"/>
            <criterion comment="acroread-libs-glib2 is earlier than 0:2.4.7-1" test_ref="oval:org.mitre.oval:tst:33249"/>
            <criterion comment="acroread-libs-gtk2 is earlier than 0:2.4.13-1.el3" test_ref="oval:org.mitre.oval:tst:33161"/>
            <criterion comment="acroread-libs-pango is earlier than 0:1.6.0-1.el3" test_ref="oval:org.mitre.oval:tst:33353"/>
            <criterion comment="acroread-libs-gtk2-engines is earlier than 0:2.2.0-1.el3" test_ref="oval:org.mitre.oval:tst:32853"/>
            <criterion comment="acroread is earlier than 0:7.0.9-1.1.1.EL3" test_ref="oval:org.mitre.oval:tst:32959"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="acroread-plugin is earlier than 0:7.0.9-1.2.0.EL4" test_ref="oval:org.mitre.oval:tst:33267"/>
            <criterion comment="acroread is earlier than 0:7.0.9-1.2.0.EL4" test_ref="oval:org.mitre.oval:tst:32938"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9683" version="5" class="vulnerability">
      <metadata>
        <title>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181"/>
        <description>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:48.539-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:26.928-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:32.319-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9683 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:34.932-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:19.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9682" version="5" class="vulnerability">
      <metadata>
        <title>Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3656" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3656"/>
        <description>Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:24.344-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:26.534-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:31.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9682 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:09.087-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:18.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37462"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37630"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36810"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36902"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37678"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37674"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37720"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37735"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37344"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37697"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37273"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37563"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37438"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37757"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37463"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37172"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9681" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775"/>
        <description>Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:29.793-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:25.977-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:31.332-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9681 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:02.799-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:17.908-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38413"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38419"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38110"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38217"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37995"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37833"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38347"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38410"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37953"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38386"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:37842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38355"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:38405"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38148"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38132"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38204"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38364"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38168"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:37685"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38372"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9680" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1341" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1341"/>
        <description>Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:52.345-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:25.795-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:31.137-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9680 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:50.788-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:17.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criterion comment="perl-DBD-Pg is earlier than 0:1.49-2.el5_3.1" test_ref="oval:org.mitre.oval:tst:38484"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9679" version="5" class="vulnerability">
      <metadata>
        <title>The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4058"/>
        <description>The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:10.182-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:25.190-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:30.480-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9679 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:10.432-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:16.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9678" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4585"/>
        <description>Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:30.846-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:24.897-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:30.217-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9678 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:00.352-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:16.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.14-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32303"/>
            <criterion comment="ethereal is earlier than 0:0.10.14-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32466"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.14-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32538"/>
            <criterion comment="ethereal is earlier than 0:0.10.14-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32039"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9677" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0599" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0599"/>
        <description>Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:28.592-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:24.609-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:29.839-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9677 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:13.623-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:15.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9676" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0113"/>
        <description>Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:23.689-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:24.404-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:29.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9676 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:18.191-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:15.594-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="httpd-devel is earlier than 0:2.0.46-32.ent" test_ref="oval:org.mitre.oval:tst:30592"/>
          <criterion comment="mod_ssl is earlier than 1:2.0.46-32.ent" test_ref="oval:org.mitre.oval:tst:30715"/>
          <criterion comment="httpd is earlier than 0:2.0.46-32.ent" test_ref="oval:org.mitre.oval:tst:30621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9675" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0411"/>
        <description>Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:46.188-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:24.084-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:29.276-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9675 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:40.678-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:15.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="systemtap-runtime is earlier than 0:0.6.2-2.el4_8.1" test_ref="oval:org.mitre.oval:tst:40200"/>
            <criterion comment="systemtap-testsuite is earlier than 0:0.6.2-2.el4_8.1" test_ref="oval:org.mitre.oval:tst:40276"/>
            <criterion comment="systemtap is earlier than 0:0.6.2-2.el4_8.1" test_ref="oval:org.mitre.oval:tst:40274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="systemtap-initscript is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39973"/>
            <criterion comment="systemtap-runtime is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39856"/>
            <criterion comment="systemtap-testsuite is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:40046"/>
            <criterion comment="systemtap-client is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:40146"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39433"/>
            <criterion comment="systemtap is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39868"/>
            <criterion comment="systemtap-server is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39484"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9674" version="5" class="vulnerability">
      <metadata>
        <title>sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0557" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0557"/>
        <description>sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:19.826-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:23.723-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:28.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9674 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:53.514-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:14.688-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30189"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30542"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30504"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30169"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29589"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30432"/>
          <criterion comment="kernel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29669"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30424"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30299"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30268"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9673" version="5" class="vulnerability">
      <metadata>
        <title>rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0154"/>
        <description>rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:18.385-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:23.539-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:28.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9673 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:35.649-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:14.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="nfs-utils is earlier than 0:1.0.6-7.EL" test_ref="oval:org.mitre.oval:tst:30663"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9672" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186, aka "the first issue."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1185"/>
        <description>Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186, aka "the first issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:41.325-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:23.211-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:28.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36267"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36295"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35708"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35618"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36334"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36509"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35698"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35872"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35719"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36068"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36582"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36568"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9671" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.  NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3603" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3603"/>
        <description>Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.  NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:41.607-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:22.950-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:28.156-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9671 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:26.115-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:14.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39383"/>
          <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39346"/>
          <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39290"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9670" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3843"/>
        <description>The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:59.672-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:22.494-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:27.654-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9670 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:54.102-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:13.460-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34804"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34557"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34837"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34795"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34562"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34357"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34379"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34873"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34870"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34374"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:967" version="2" class="vulnerability">
      <metadata>
        <title>rsync Path Sanitation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0426"/>
        <description>rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:48.553-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.957-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="rsync version is less than 2.5.7-4.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1389"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9669" version="5" class="vulnerability">
      <metadata>
        <title>The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2496" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2496"/>
        <description>The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:24.524-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:22.313-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:27.453-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9669 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:44.898-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:13.175-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="ntp is earlier than 0:4.2.0.a.20040617-4.EL4.1" test_ref="oval:org.mitre.oval:tst:32391"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9668" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2808" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2808"/>
        <description>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:55.758-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:21.688-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:26.787-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9668 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:04.977-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:12.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9667" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5498" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5498"/>
        <description>Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:47.545-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:20.943-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:25.995-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9667 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:16.534-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:11.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:38010"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37683"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37468"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37994"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37569"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37746"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38324"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38288"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38029"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:37974"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38154"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38499"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38401"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38018"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38505"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38494"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38075"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38387"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38058"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38147"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38305"/>
            <criterion comment="php-common is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38268"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38298"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37882"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37952"/>
            <criterion comment="php is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38099"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38415"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38511"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38115"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38367"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38569"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38440"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38536"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38507"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38316"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38493"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37667"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9666" version="5" class="vulnerability">
      <metadata>
        <title>The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3641" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3641"/>
        <description>The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:34.316-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:20.603-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:25.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9666 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:07.539-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:10.865-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:37294"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:37772"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:37394"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:37546"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:37714"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:37699"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37215"/>
            <criterion comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37378"/>
            <criterion comment="cups is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37794"/>
            <criterion comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37702"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9665" version="5" class="vulnerability">
      <metadata>
        <title>The BER dissector in Ethereal 0.10.3 to 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3244"/>
        <description>The BER dissector in Ethereal 0.10.3 to 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:40.827-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:20.362-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:25.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9665 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:12.804-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:10.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32189"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32138"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32341"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32202"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9664" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2905" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2905"/>
        <description>Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:35.218-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:20.074-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:25.053-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9664 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:04.811-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:09.989-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="newt-devel is earlier than 0:0.51.5-2.el3" test_ref="oval:org.mitre.oval:tst:39137"/>
            <criterion comment="newt is earlier than 0:0.51.5-2.el3" test_ref="oval:org.mitre.oval:tst:39439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="newt-devel is earlier than 0:0.51.6-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:39340"/>
            <criterion comment="newt is earlier than 0:0.51.6-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:39343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="newt-devel is earlier than 0:0.52.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:39387"/>
            <criterion comment="newt is earlier than 0:0.52.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:38962"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9663" version="5" class="vulnerability">
      <metadata>
        <title>The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1377"/>
        <description>The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:40.143-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:19.814-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:24.788-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9663 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:05.909-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:09.678-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5" test_ref="oval:org.mitre.oval:tst:39059"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5" test_ref="oval:org.mitre.oval:tst:38295"/>
          <criterion comment="openssl is earlier than 0:0.9.8e-12.el5" test_ref="oval:org.mitre.oval:tst:38660"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9662" version="5" class="vulnerability">
      <metadata>
        <title>The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5510" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5510"/>
        <description>The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:43.646-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:19.436-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:24.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9662 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:27.567-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:09.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:37631"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38114"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37737"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9661" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable expansion such as tilde expansion for the HOME environment variable, and (3) a long -f (aka reffile) command line argument.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4262"/>
        <description>Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable expansion such as tilde expansion for the HOME environment variable, and (3) a long -f (aka reffile) command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:21.720-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:19.213-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:24.162-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9661 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:35.114-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:08.754-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-16.RHEL3" test_ref="oval:org.mitre.oval:tst:38743"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-10.RHEL4.3" test_ref="oval:org.mitre.oval:tst:38662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9660" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafted SWF file that "dynamically unloads itself from an outside JavaScript function," which triggers an access of an expired memory address.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5013"/>
        <description>Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafted SWF file that "dynamically unloads itself from an outside JavaScript function," which triggers an access of an expired memory address.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:29.645-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:18.788-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:23.715-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9660 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:08.551-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:08.233-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9659" version="5" class="vulnerability">
      <metadata>
        <title>fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without headers from upstream mail servers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4348" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4348"/>
        <description>fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without headers from upstream mail servers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:40.544-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:18.572-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:23.480-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9659 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:10.193-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:07.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.0-3.el3.3" test_ref="oval:org.mitre.oval:tst:33046"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.5-6.el4.5" test_ref="oval:org.mitre.oval:tst:33350"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9658" version="5" class="vulnerability">
      <metadata>
        <title>The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1184"/>
        <description>The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:18.437-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:18.349-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:23.245-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9658 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:46.788-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:07.373-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-24.4" test_ref="oval:org.mitre.oval:tst:30796"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-28.3" test_ref="oval:org.mitre.oval:tst:31274"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9657" version="5" class="vulnerability">
      <metadata>
        <title>Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0967" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0967"/>
        <description>Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:58.882-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:18.132-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:22.969-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9657 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:50.647-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:06.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el3" test_ref="oval:org.mitre.oval:tst:31686"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el4" test_ref="oval:org.mitre.oval:tst:31403"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9656" version="5" class="vulnerability">
      <metadata>
        <title>Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4988"/>
        <description>Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:23.974-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:17.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:22.353-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9656 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:53.345-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:06.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36023"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36184"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36260"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36208"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36311"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36459"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36349"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35927"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36419"/>
            <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36360"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36388"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35921"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36133"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9655" version="5" class="vulnerability">
      <metadata>
        <title>The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have unspecified other impact via vectors involving modification of the futex value from user space.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0622" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0622"/>
        <description>The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have unspecified other impact via vectors involving modification of the futex value from user space.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:00.784-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:17.345-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:21.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9655 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:25.839-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:05.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40501"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40283"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40807"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40842"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40793"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40732"/>
          <criterion comment="kernel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40830"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40349"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39978"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39896"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40791"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40580"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9654" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1467" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1467"/>
        <description>Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:39.939-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:16.840-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:21.722-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9654 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:37.931-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:05.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9653" version="5" class="vulnerability">
      <metadata>
        <title>The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3183"/>
        <description>The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:13.552-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:16.636-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:21.503-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9653 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:58.745-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:05.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="w3c-libwww-devel is earlier than 0:5.4.0-10.1.RHEL4.2" test_ref="oval:org.mitre.oval:tst:33967"/>
          <criterion comment="w3c-libwww is earlier than 0:5.4.0-10.1.RHEL4.2" test_ref="oval:org.mitre.oval:tst:34049"/>
          <criterion comment="w3c-libwww-apps is earlier than 0:5.4.0-10.1.RHEL4.2" test_ref="oval:org.mitre.oval:tst:34020"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9652" version="5" class="vulnerability">
      <metadata>
        <title>pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1384"/>
        <description>pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:00.760-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:16.455-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:21.307-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9652 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:06.388-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:04.825-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criterion comment="pam_krb5 is earlier than 0:2.2.14-15" test_ref="oval:org.mitre.oval:tst:40172"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9651" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1237" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1237"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:55.698-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:15.889-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:20.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9651 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:22.592-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:04.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9650" version="5" class="vulnerability">
      <metadata>
        <title>The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0401" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0401"/>
        <description>FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:22.001-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:15.384-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:20.211-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9650 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:45.764-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:03.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30665"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31499"/>
            <criterion comment="mozilla is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31604"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31381"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31622"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30651"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31560"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31110"/>
            <criterion comment="evolution is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31003"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31404"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31375"/>
            <criterion comment="firefox is earlier than 0:1.0.2-1.4.1" test_ref="oval:org.mitre.oval:tst:31302"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31106"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31418"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9649" version="5" class="vulnerability">
      <metadata>
        <title>The kernel in Red Hat Enterprise Linux 3, when running on SMP systems, allows local users to cause a denial of service (deadlock) by running the shmat function on an shm at the same time that shmctl is removing that shm (IPC_RMID), which prevents a spinlock from being unlocked.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4342" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4342"/>
        <description>The kernel in Red Hat Enterprise Linux 3, when running on SMP systems, allows local users to cause a denial of service (deadlock) by running the shmat function on an shm at the same time that shmctl is removing that shm (IPC_RMID), which prevents a spinlock from being unlocked.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:35.508-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:15.104-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:19.865-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9649 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:38.372-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:03.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33074"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32633"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33103"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33001"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32937"/>
          <criterion comment="kernel is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32280"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33127"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32855"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33021"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9648" version="5" class="vulnerability">
      <metadata>
        <title>The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4814"/>
        <description>The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:22.505-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:14.645-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:19.433-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9648 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:07.524-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:02.479-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35915"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35794"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36513"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36264"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36161"/>
            <criterion comment="kernel is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36518"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36597"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36612"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9647" version="5" class="vulnerability">
      <metadata>
        <title>The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2553"/>
        <description>The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:16.353-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:14.360-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:19.138-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9647 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:14.004-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:02.105-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
          <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9646" version="5" class="vulnerability">
      <metadata>
        <title>The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2664"/>
        <description>The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:29.319-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:13.814-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:18.590-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9646 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:37.324-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:01.366-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9645" version="5" class="vulnerability">
      <metadata>
        <title>Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1165"/>
        <description>Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:33.502-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:13.548-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:18.310-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9645 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:31.530-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:00.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.1.3-5.8" test_ref="oval:org.mitre.oval:tst:31113"/>
            <criterion comment="kdebase-devel is earlier than 6:3.1.3-5.8" test_ref="oval:org.mitre.oval:tst:31092"/>
            <criterion comment="kdelibs is earlier than 6:3.1.3-6.9" test_ref="oval:org.mitre.oval:tst:30244"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.1.3-6.9" test_ref="oval:org.mitre.oval:tst:30826"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs is earlier than 6:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:31221"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:30975"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9644" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2358" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2358"/>
        <description>Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:17.061-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:13.236-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:17.926-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9644 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:00.946-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:00.460-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36992"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:37039"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36460"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36799"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:37005"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:37063"/>
          <criterion comment="kernel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36981"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36704"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36937"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36703"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36996"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36869"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9643" version="5" class="vulnerability">
      <metadata>
        <title>The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3835"/>
        <description>The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:58.351-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:12.714-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:17.442-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9643 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:23.890-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:59.773-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9642" version="5" class="vulnerability">
      <metadata>
        <title>nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5021"/>
        <description>nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:55.209-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:12.109-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:16.777-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9642 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:22.254-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:58.939-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9641" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3274"/>
        <description>Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:58.227-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:11.501-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:16.210-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9641 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:12.067-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:58.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39570"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39466"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39720"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39691"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39583"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39727"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39575"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39481"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39675"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39683"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39031"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39547"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39753"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9640" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0468" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0468"/>
        <description>Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:52.520-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:11.141-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:15.765-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9640 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:34.936-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:57.484-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31573"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31050"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31373"/>
            <criterion comment="telnet is earlier than 1:0.17-26.EL3.2" test_ref="oval:org.mitre.oval:tst:31054"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31472"/>
            <criterion comment="telnet-server is earlier than 1:0.17-26.EL3.2" test_ref="oval:org.mitre.oval:tst:31463"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31015"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31409"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:30952"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31575"/>
            <criterion comment="telnet is earlier than 1:0.17-31.EL4.2" test_ref="oval:org.mitre.oval:tst:31498"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31481"/>
            <criterion comment="telnet-server is earlier than 1:0.17-31.EL4.2" test_ref="oval:org.mitre.oval:tst:31275"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31526"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9639" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1751"/>
        <description>Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:12.818-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:10.629-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:15.296-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9639 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:47.453-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:56.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31903"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31997"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:32058"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:32011"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31769"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31610"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:32022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31993"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31996"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:32047"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31303"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31718"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31829"/>
            <criterion comment="php is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31181"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:32064"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31623"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31882"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31988"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:32010"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31662"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31873"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9638" version="5" class="vulnerability">
      <metadata>
        <title>The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via a new session keyring (1) with an empty name string, (2) with a long name string, (3) with the key quota reached, or (4) ENOMEM.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2098"/>
        <description>The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via a new session keyring (1) with an empty name string, (2) with a long name string, (3) with the key quota reached, or (4) ENOMEM.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:06.868-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:10.370-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:14.983-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9638 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:33.919-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:56.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9637" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4566"/>
        <description>Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:17.073-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:09.831-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:14.486-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9637 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:15.289-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:55.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32910"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9636" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file.  NOTE: this issue is due to an incomplete fix for CVE-2004-0888.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1374"/>
        <description>Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file.  NOTE: this issue is due to an incomplete fix for CVE-2004-0888.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:28.387-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:09.568-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:14.202-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9636 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:58.347-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:55.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.52" test_ref="oval:org.mitre.oval:tst:36146"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.52" test_ref="oval:org.mitre.oval:tst:36214"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.52" test_ref="oval:org.mitre.oval:tst:36403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" test_ref="oval:org.mitre.oval:tst:36474"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" test_ref="oval:org.mitre.oval:tst:35913"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" test_ref="oval:org.mitre.oval:tst:36036"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9635" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in a certain Red Hat build script for Standards Based Linux Instrumentation for Manageability (sblim) libraries before 1-13a.el4_6.1 in Red Hat Enterprise Linux (RHEL) 4, and before 1-31.el5_2.1 in RHEL 5, allows local users to gain privileges via a malicious library in a certain subdirectory of /var/tmp, related to an incorrect RPATH setting, as demonstrated by a malicious libc.so library for tog-pegasus.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1951" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1951"/>
        <description>Untrusted search path vulnerability in a certain Red Hat build script for Standards Based Linux Instrumentation for Manageability (sblim) libraries before 1-13a.el4_6.1 in Red Hat Enterprise Linux (RHEL) 4, and before 1-31.el5_2.1 in RHEL 5, allows local users to gain privileges via a malicious library in a certain subdirectory of /var/tmp, related to an incorrect RPATH setting, as demonstrated by a malicious libc.so library for tog-pegasus.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:25.732-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:08.533-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:13.150-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9635 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:29.302-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:54.200-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sblim-cmpi-nfsv3-test is earlier than 0:1.0.13-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36852"/>
            <criterion comment="sblim-cmpi-params is earlier than 0:1.2.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36779"/>
            <criterion comment="sblim-cmpi-nfsv3 is earlier than 0:1.0.13-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36564"/>
            <criterion comment="sblim-cmpi-devel is earlier than 0:1.0.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36536"/>
            <criterion comment="sblim-wbemcli is earlier than 0:1.5.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36791"/>
            <criterion comment="sblim-cmpi-nfsv4 is earlier than 0:1.0.11-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36824"/>
            <criterion comment="sblim-cmpi-fsvol-test is earlier than 0:1.4.3-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36765"/>
            <criterion comment="sblim-cmpi-network is earlier than 0:1.3.7-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36588"/>
            <criterion comment="sblim-cmpi-syslog is earlier than 0:0.7.9-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36247"/>
            <criterion comment="sblim-cmpi-syslog-test is earlier than 0:0.7.9-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36076"/>
            <criterion comment="sblim-cmpi-fsvol is earlier than 0:1.4.3-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36660"/>
            <criterion comment="sblim-gather-devel is earlier than 0:2.1.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36712"/>
            <criterion comment="sblim-cmpi-network-test is earlier than 0:1.3.7-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36650"/>
            <criterion comment="sblim-cmpi-fsvol-devel is earlier than 0:1.4.3-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36717"/>
            <criterion comment="sblim-cmpi-network-devel is earlier than 0:1.3.7-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36209"/>
            <criterion comment="sblim-gather-test is earlier than 0:2.1.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36775"/>
            <criterion comment="sblim-cmpi-base is earlier than 0:1.5.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36759"/>
            <criterion comment="sblim-gather-provider is earlier than 0:2.1.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36250"/>
            <criterion comment="sblim-cmpi-params-test is earlier than 0:1.2.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36849"/>
            <criterion comment="sblim-cmpi-nfsv4-test is earlier than 0:1.0.11-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36095"/>
            <criterion comment="sblim-cmpi-sysfs is earlier than 0:1.1.8-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36718"/>
            <criterion comment="sblim-cmpi-base-test is earlier than 0:1.5.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36724"/>
            <criterion comment="sblim-cmpi-base-devel is earlier than 0:1.5.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36680"/>
            <criterion comment="sblim is earlier than 0:1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36800"/>
            <criterion comment="sblim-testsuite is earlier than 0:1.2.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36753"/>
            <criterion comment="sblim-gather is earlier than 0:2.1.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36780"/>
            <criterion comment="sblim-cmpi-sysfs-test is earlier than 0:1.1.8-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36842"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sblim-cim-client-javadoc is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36701"/>
            <criterion comment="sblim-wbemcli is earlier than 0:1.5.1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36793"/>
            <criterion comment="sblim-cmpi-samba-test is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36850"/>
            <criterion comment="sblim-cmpi-nfsv4 is earlier than 0:1.0.12-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36447"/>
            <criterion comment="sblim-cmpi-fsvol-test is earlier than 0:1.4.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36689"/>
            <criterion comment="sblim-cmpi-syslog is earlier than 0:0.7.11-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36783"/>
            <criterion comment="sblim-cmpi-fsvol is earlier than 0:1.4.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36787"/>
            <criterion comment="sblim-cmpi-fsvol-devel is earlier than 0:1.4.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36899"/>
            <criterion comment="sblim-gather-test is earlier than 0:2.1.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:35986"/>
            <criterion comment="sblim-gather-provider is earlier than 0:2.1.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36687"/>
            <criterion comment="sblim-cmpi-params-test is earlier than 0:1.2.6-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36673"/>
            <criterion comment="sblim-cmpi-dns is earlier than 0:0.5.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36001"/>
            <criterion comment="sblim-cmpi-dns-test is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36196"/>
            <criterion comment="sblim-cmpi-samba-devel is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36797"/>
            <criterion comment="sblim-cmpi-dns-devel is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36692"/>
            <criterion comment="sblim-testsuite is earlier than 0:1.2.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36633"/>
            <criterion comment="sblim-gather is earlier than 0:2.1.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36802"/>
            <criterion comment="sblim-tools-libra is earlier than 0:0.2.3-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36489"/>
            <criterion comment="sblim-cmpi-nfsv3-test is earlier than 0:1.0.14-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36714"/>
            <criterion comment="sblim-cmpi-devel is earlier than 0:1.0.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36888"/>
            <criterion comment="sblim-cmpi-nfsv3 is earlier than 0:1.0.14-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36479"/>
            <criterion comment="sblim-cmpi-params is earlier than 0:1.2.6-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36857"/>
            <criterion comment="sblim-tools-libra-devel is earlier than 0:0.2.3-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36970"/>
            <criterion comment="sblim-cmpi-network is earlier than 0:1.3.8-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36578"/>
            <criterion comment="sblim-cmpi-syslog-test is earlier than 0:0.7.11-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:35968"/>
            <criterion comment="sblim-cmpi-network-test is earlier than 0:1.3.8-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36896"/>
            <criterion comment="sblim-gather-devel is earlier than 0:2.1.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36721"/>
            <criterion comment="sblim-cmpi-network-devel is earlier than 0:1.3.8-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36890"/>
            <criterion comment="sblim-cmpi-base is earlier than 0:1.5.5-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36892"/>
            <criterion comment="sblim-cim-client is earlier than 0:1.3.3-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36709"/>
            <criterion comment="sblim-cmpi-nfsv4-test is earlier than 0:1.0.12-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36856"/>
            <criterion comment="sblim-cim-client-manual is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36889"/>
            <criterion comment="sblim-cmpi-sysfs is earlier than 0:1.1.9-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:35937"/>
            <criterion comment="sblim-cmpi-base-test is earlier than 0:1.5.5-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36354"/>
            <criterion comment="sblim-cmpi-samba is earlier than 0:0.5.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:35992"/>
            <criterion comment="sblim is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36245"/>
            <criterion comment="sblim-cmpi-base-devel is earlier than 0:1.5.5-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36624"/>
            <criterion comment="sblim-cmpi-sysfs-test is earlier than 0:1.1.9-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36863"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9634" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159"/>
        <description>Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:50.551-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:08.263-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:12.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9634 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:38.616-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:53.699-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.1.2-6.el3" test_ref="oval:org.mitre.oval:tst:39300"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.2" test_ref="oval:org.mitre.oval:tst:38589"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5_3.2" test_ref="oval:org.mitre.oval:tst:38719"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9633" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0148"/>
        <description>Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:48.722-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:07.962-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:12.554-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9633 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:30.994-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:53.267-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-16.RHEL3" test_ref="oval:org.mitre.oval:tst:38743"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-10.RHEL4.3" test_ref="oval:org.mitre.oval:tst:38662"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-15.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38706"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9632" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0146" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146"/>
        <description>Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:58.393-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:07.366-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:11.756-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9632 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:15.795-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:52.340-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9631" version="5" class="vulnerability">
      <metadata>
        <title>The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0949"/>
        <description>The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:10.975-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:06.986-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:11.407-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9631 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:49.651-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:51.784-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.62" test_ref="oval:org.mitre.oval:tst:38765"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.62" test_ref="oval:org.mitre.oval:tst:37797"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.62" test_ref="oval:org.mitre.oval:tst:38735"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" test_ref="oval:org.mitre.oval:tst:38351"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" test_ref="oval:org.mitre.oval:tst:38503"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" test_ref="oval:org.mitre.oval:tst:38748"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:38713"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:38764"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:38681"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:38653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9630" version="5" class="vulnerability">
      <metadata>
        <title>net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0007"/>
        <description>net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:12.864-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:06.379-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:10.854-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9630 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:47.681-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:51.155-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40241"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40097"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40139"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40308"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40210"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40082"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40354"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40326"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:39940"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:39363"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:39805"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40228"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40098"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40231"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39918"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39938"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40088"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40237"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39997"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40240"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40352"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39930"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40055"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9629" version="5" class="vulnerability">
      <metadata>
        <title>The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-6472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6472"/>
        <description>The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:57.215-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:06.089-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:10.553-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9629 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:54.445-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:50.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9628" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2114"/>
        <description>Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:45.537-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:05.549-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:10.068-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9628 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:17.225-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:49.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32142"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32131"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32154"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32001"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32171"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32162"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31782"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32041"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32004"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32120"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31633"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31837"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32100"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31821"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31904"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31814"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31951"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31554"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32149"/>
            <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31998"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32061"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9627" version="5" class="vulnerability">
      <metadata>
        <title>The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447"/>
        <description>The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:23.903-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:04.970-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:09.484-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9627 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:41.687-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:49.236-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:37016"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:37047"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:36733"/>
            <criterion comment="bind is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:36959"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:37048"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:36719"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:36575"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:37082"/>
            <criterion comment="selinux-policy-targeted is earlier than 0:1.17.30-2.150.el4" test_ref="oval:org.mitre.oval:tst:36876"/>
            <criterion comment="selinux-policy-targeted-sources is earlier than 0:1.17.30-2.150.el4" test_ref="oval:org.mitre.oval:tst:37007"/>
            <criterion comment="bind is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:36100"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:36925"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:37003"/>
            <criterion comment="bind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:37017"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36924"/>
            <criterion comment="selinux-policy-targeted is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:37069"/>
            <criterion comment="dnsmasq is earlier than 0:2.45-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:37588"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36601"/>
            <criterion comment="bind is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36960"/>
            <criterion comment="bind-utils is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36962"/>
            <criterion comment="selinux-policy-devel is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:36667"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36806"/>
            <criterion comment="selinux-policy is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:36092"/>
            <criterion comment="bind-libs is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:37038"/>
            <criterion comment="selinux-policy-strict is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:36853"/>
            <criterion comment="selinux-policy-mls is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:36790"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9626" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6502" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6502"/>
        <description>Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:40.379-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:04.480-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:08.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9626 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:02.219-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:48.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32785"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33227"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33266"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33146"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32352"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33183"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33095"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32996"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33195"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33229"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33273"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33259"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33239"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33284"/>
            <criterion comment="firefox is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32815"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33153"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33015"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33251"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33336"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32408"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9625" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0882"/>
        <description>Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:25.707-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:04.262-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:08.691-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9625 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:27.364-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:47.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="cups-lpd is earlier than 0:1.2.4-11.14.el5_1.4" test_ref="oval:org.mitre.oval:tst:36112"/>
          <criterion comment="cups-devel is earlier than 0:1.2.4-11.14.el5_1.4" test_ref="oval:org.mitre.oval:tst:36033"/>
          <criterion comment="cups is earlier than 0:1.2.4-11.14.el5_1.4" test_ref="oval:org.mitre.oval:tst:36231"/>
          <criterion comment="cups-libs is earlier than 0:1.2.4-11.14.el5_1.4" test_ref="oval:org.mitre.oval:tst:36453"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9624" version="5" class="vulnerability">
      <metadata>
        <title>racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1574"/>
        <description>racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:18.798-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:04.081-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:08.493-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9624 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:15.647-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:47.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criterion comment="ipsec-tools is earlier than 0:0.6.5-13.el5_3.1" test_ref="oval:org.mitre.oval:tst:38789"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9623" version="5" class="vulnerability">
      <metadata>
        <title>BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4096"/>
        <description>BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:55.413-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:03.723-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:08.164-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9623 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:09.956-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:46.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:30151"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:30374"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:30138"/>
            <criterion comment="bind is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:29802"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:30540"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30310"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30454"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30510"/>
            <criterion comment="bind is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30416"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30409"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9622" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5340" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5340"/>
        <description>Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:56.515-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:03.196-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:07.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9622 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:37.498-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:46.115-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35512"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35540"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35394"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35541"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35553"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35552"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:34924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35155"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35489"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35324"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" test_ref="oval:org.mitre.oval:tst:35240"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35182"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35311"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35454"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.7.el4" test_ref="oval:org.mitre.oval:tst:35398"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35351"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35482"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34790"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35291"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35262"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35202"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-5.el5" test_ref="oval:org.mitre.oval:tst:35177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9621" version="3" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, and Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, allow attackers to develop Java applets or applications that are able to gain privileges, related to serialization in JRE.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6745"/>
        <description>Multiple unspecified vulnerabilities in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, and Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, allow attackers to develop Java applets or applications that are able to gain privileges, related to serialization in JRE.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:09.707-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:02.725-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:07.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criteria operator="OR">
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33298"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33521"/>
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33376"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33428"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33515"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.7-1jpp.4.el3" test_ref="oval:org.mitre.oval:tst:33417"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:32803"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33585"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33064"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33481"/>
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33563"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33479"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33472"/>
            <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:32903"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33667"/>
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33199"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33754"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.3-1jpp.3.el4" test_ref="oval:org.mitre.oval:tst:33366"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33073"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.7-1jpp.4.el4" test_ref="oval:org.mitre.oval:tst:33547"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9620" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3933" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3933"/>
        <description>Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:51.000-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:02.435-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:06.806-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9620 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:00.406-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:45.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9619" version="5" class="vulnerability">
      <metadata>
        <title>Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0547"/>
        <description>Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:31.976-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:01.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:06.494-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9619 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:37.893-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:45.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution28-evolution-data-server-devel is earlier than 0:1.8.0-37.el4_7.2" test_ref="oval:org.mitre.oval:tst:38140"/>
            <criterion comment="evolution-data-server-devel is earlier than 0:1.0.2-14.el4_7.1" test_ref="oval:org.mitre.oval:tst:38464"/>
            <criterion comment="evolution-data-server is earlier than 0:1.0.2-14.el4_7.1" test_ref="oval:org.mitre.oval:tst:38477"/>
            <criterion comment="evolution is earlier than 0:2.0.2-41.el4_7.2" test_ref="oval:org.mitre.oval:tst:38489"/>
            <criterion comment="evolution28-evolution-data-server is earlier than 0:1.8.0-37.el4_7.2" test_ref="oval:org.mitre.oval:tst:38193"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-41.el4_7.2" test_ref="oval:org.mitre.oval:tst:38059"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution-data-server-devel is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:38514"/>
            <criterion comment="evolution-data-server is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:37983"/>
            <criterion comment="evolution-data-server-doc is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:37891"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9618" version="5" class="vulnerability">
      <metadata>
        <title>slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4600" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4600"/>
        <description>slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:53.371-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:01.349-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:06.164-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9618 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:57.699-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:44.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openldap-devel is earlier than 0:2.0.27-23" test_ref="oval:org.mitre.oval:tst:34514"/>
            <criterion comment="openldap-clients is earlier than 0:2.0.27-23" test_ref="oval:org.mitre.oval:tst:34458"/>
            <criterion comment="openldap is earlier than 0:2.0.27-23" test_ref="oval:org.mitre.oval:tst:34561"/>
            <criterion comment="openldap-servers is earlier than 0:2.0.27-23" test_ref="oval:org.mitre.oval:tst:33949"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="compat-openldap is earlier than 0:2.1.30-7.4E" test_ref="oval:org.mitre.oval:tst:33968"/>
            <criterion comment="openldap-devel is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:34054"/>
            <criterion comment="openldap-clients is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:34115"/>
            <criterion comment="openldap is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:34114"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:34101"/>
            <criterion comment="openldap-servers is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:33882"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9617" version="5" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in FastJar 0.93, as used in Gnu GCC 4.1.1 and earlier, and 3.4.6 and earlier, allows user-assisted attackers to overwrite arbitrary files via a .jar file containing filenames with "../" sequences.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3619" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3619"/>
        <description>Directory traversal vulnerability in FastJar 0.93, as used in Gnu GCC 4.1.1 and earlier, and 3.4.6 and earlier, allows user-assisted attackers to overwrite arbitrary files via a .jar file containing filenames with "../" sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:09.813-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:00.682-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:05.480-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9617 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:50.705-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:43.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gcc-ppc32 is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34573"/>
            <criterion comment="gcc-java is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34533"/>
            <criterion comment="gcc-g77 is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34680"/>
            <criterion comment="libgcj is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34364"/>
            <criterion comment="gcc-c++ is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34558"/>
            <criterion comment="libobjc is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34188"/>
            <criterion comment="libstdc++ is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34631"/>
            <criterion comment="libf2c is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34315"/>
            <criterion comment="gcc-c++-ppc32 is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34518"/>
            <criterion comment="gcc-objc is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34287"/>
            <criterion comment="libgnat is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34120"/>
            <criterion comment="libstdc++-devel is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34471"/>
            <criterion comment="gcc-gnat is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34329"/>
            <criterion comment="cpp is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34617"/>
            <criterion comment="libgcj-devel is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:33808"/>
            <criterion comment="gcc is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34691"/>
            <criterion comment="libgcc is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:33732"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gcc-ppc32 is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33781"/>
            <criterion comment="gcc-java is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33255"/>
            <criterion comment="gcc-g77 is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33431"/>
            <criterion comment="libgcj is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33641"/>
            <criterion comment="gcc-c++ is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33545"/>
            <criterion comment="libobjc is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33752"/>
            <criterion comment="libstdc++ is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34001"/>
            <criterion comment="libf2c is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33787"/>
            <criterion comment="gcc-c++-ppc32 is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34089"/>
            <criterion comment="gcc-objc is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33916"/>
            <criterion comment="libgnat is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33942"/>
            <criterion comment="libstdc++-devel is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33437"/>
            <criterion comment="gcc-gnat is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34105"/>
            <criterion comment="cpp is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34086"/>
            <criterion comment="libgcj-devel is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34100"/>
            <criterion comment="gcc is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34111"/>
            <criterion comment="libgcc is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34014"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9616" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0102"/>
        <description>Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:08.344-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:00.432-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:05.220-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9616 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:56.892-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:43.443-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:1.4.5-14" test_ref="oval:org.mitre.oval:tst:31420"/>
            <criterion comment="evolution-devel is earlier than 0:1.4.5-14" test_ref="oval:org.mitre.oval:tst:30692"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:2.0.2-16" test_ref="oval:org.mitre.oval:tst:31620"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-16" test_ref="oval:org.mitre.oval:tst:31842"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9615" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2495"/>
        <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:49.534-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:59.608-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:04.403-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9615 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:15.413-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:42.488-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31985"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31627"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31972"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31705"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31773"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31675"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:32017"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31942"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31963"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31156"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31574"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31905"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31784"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31310"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31908"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31949"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31827"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31806"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31649"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31020"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31743"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31721"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31883"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31764"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31959"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31843"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31616"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31732"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31371"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31803"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31419"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31188"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31835"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31397"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:30870"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31767"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31614"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31663"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31651"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31689"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31765"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31036"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:30807"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31179"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31491"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31427"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31761"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31667"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9614" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0493"/>
        <description>Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:09.379-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:59.323-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:04.114-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9614 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:05.309-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:42.086-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="bind-utils is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33237"/>
          <criterion comment="bind-libbind-devel is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:32565"/>
          <criterion comment="bind-devel is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33314"/>
          <criterion comment="bind-chroot is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:32936"/>
          <criterion comment="caching-nameserver is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33164"/>
          <criterion comment="bind-sdb is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33109"/>
          <criterion comment="bind is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33115"/>
          <criterion comment="bind-libs is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9613" version="5" class="vulnerability">
      <metadata>
        <title>unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0990"/>
        <description>unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:22.778-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:59.101-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:03.826-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9613 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:19.894-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:41.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="sharutils is earlier than 0:4.2.1-16.2" test_ref="oval:org.mitre.oval:tst:31587"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="sharutils is earlier than 0:4.2.1-22.2" test_ref="oval:org.mitre.oval:tst:31528"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9612" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083"/>
        <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:37.688-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:58.510-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:03.293-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9612 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:01.474-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:41.055-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30567"/>
          <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30064"/>
          <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30460"/>
          <criterion comment="XFree86-libs is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:29952"/>
          <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30100"/>
          <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30258"/>
          <criterion comment="XFree86-twm is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30560"/>
          <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30714"/>
          <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30316"/>
          <criterion comment="XFree86-doc is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30669"/>
          <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:29808"/>
          <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:29998"/>
          <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30273"/>
          <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30537"/>
          <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:29649"/>
          <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30610"/>
          <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30489"/>
          <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30530"/>
          <criterion comment="XFree86-xdm is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30518"/>
          <criterion comment="XFree86 is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30588"/>
          <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30206"/>
          <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30113"/>
          <criterion comment="XFree86-xfs is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30525"/>
          <criterion comment="XFree86-tools is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30631"/>
          <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30636"/>
          <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30500"/>
          <criterion comment="XFree86-xauth is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30123"/>
          <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30593"/>
          <criterion comment="XFree86-devel is earlier than 0:4.3.0-55.EL" test_ref="oval:org.mitre.oval:tst:30503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9611" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3802" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3802"/>
        <description>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:41.250-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:57.979-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:02.759-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9611 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:40.461-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:40.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9610" version="5" class="vulnerability">
      <metadata>
        <title>SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1454" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1454"/>
        <description>SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:11.283-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:57.719-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:02.495-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9610 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:19.612-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:39.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="freeradius is earlier than 0:1.0.1-1.1.RHEL3" test_ref="oval:org.mitre.oval:tst:31698"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:32002"/>
            <criterion comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31962"/>
            <criterion comment="freeradius is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31992"/>
            <criterion comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9609" version="5" class="vulnerability">
      <metadata>
        <title>The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772"/>
        <description>The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:20.634-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:57.190-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:01.571-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9609 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:56.765-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:39.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38413"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38419"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38110"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38217"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37995"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37833"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38347"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38410"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37953"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38386"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:37842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38355"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:38405"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38148"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38132"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38204"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38364"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38168"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:37685"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38372"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9608" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2871"/>
        <description>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:03.463-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:56.553-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:01.088-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9608 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:55.287-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:38.577-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31744"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32124"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32082"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32187"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32043"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32006"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32183"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32139"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31801"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32194"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32134"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32161"/>
            <criterion comment="thunderbird is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:31477"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32155"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32024"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:31724"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32126"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:31884"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32021"/>
            <criterion comment="firefox is earlier than 0:1.0.6-1.4.2" test_ref="oval:org.mitre.oval:tst:32145"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:31660"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32157"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9607" version="5" class="vulnerability">
      <metadata>
        <title>The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5188"/>
        <description>The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:10.713-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:56.340-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:00.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9607 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:53.282-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:38.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5" test_ref="oval:org.mitre.oval:tst:38822"/>
          <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5" test_ref="oval:org.mitre.oval:tst:39084"/>
          <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5" test_ref="oval:org.mitre.oval:tst:39213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9606" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the "REALLOC_N" variant, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2664.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2725"/>
        <description>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the "REALLOC_N" variant, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2664.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:21.744-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:55.744-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:00.236-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9606 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:06.662-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:37.531-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9605" version="5" class="vulnerability">
      <metadata>
        <title>packet-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a malformed USB Request Block (URB).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4680" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4680"/>
        <description>packet-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a malformed USB Request Block (URB).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:09.474-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:55.446-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:59.893-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9605 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:13.502-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:36.826-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9604" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:26.455-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:54.903-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:59.390-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9604 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:08.087-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:36.196-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9603" version="5" class="vulnerability">
      <metadata>
        <title>JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2689"/>
        <description>JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:25.496-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:54.670-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:59.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9603 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:41.292-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:35.795-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38942"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38825"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38972"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38267"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:39037"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9602" version="5" class="vulnerability">
      <metadata>
        <title>The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3873" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3873"/>
        <description>The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:16.494-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:54.436-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:58.840-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9602 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:24.713-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:35.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:38878"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39616"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39115"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39531"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39655"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9601" version="5" class="vulnerability">
      <metadata>
        <title>tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1279" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1279"/>
        <description>tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:01.848-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:54.175-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:58.577-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9601 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:20.339-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:34.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libpcap is earlier than 14:0.7.2-7.E3.5" test_ref="oval:org.mitre.oval:tst:31652"/>
            <criterion comment="tcpdump is earlier than 14:3.7.2-7.E3.5" test_ref="oval:org.mitre.oval:tst:31836"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-9.RHEL4" test_ref="oval:org.mitre.oval:tst:31864"/>
            <criterion comment="libpcap is earlier than 14:0.8.3-9.RHEL4" test_ref="oval:org.mitre.oval:tst:30922"/>
            <criterion comment="tcpdump is earlier than 14:3.8.2-9.RHEL4" test_ref="oval:org.mitre.oval:tst:31788"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9600" version="5" class="vulnerability">
      <metadata>
        <title>The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0834"/>
        <description>The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:09.524-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:53.633-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:58.095-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9600 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:18:04.409-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:34.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38437"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38348"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:37805"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38116"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38721"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38384"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38346"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38490"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38262"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38289"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38302"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38663"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38680"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38674"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38654"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38700"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38368"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38726"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38390"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38547"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38412"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38701"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38129"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:960" version="1" class="vulnerability">
      <metadata>
        <title>Magick XWD Decoder DoS</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1739"/>
        <description>The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ImageMagick RPM earlier than 0:5.5.6-15" negate="false" test_ref="oval:org.mitre.oval:tst:1397"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9599" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0585"/>
        <description>Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:43.432-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:53.363-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:57.773-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9599 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:12.920-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:33.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libsoup is earlier than 0:2.2.1-4.el4.1" test_ref="oval:org.mitre.oval:tst:38290"/>
            <criterion comment="evolution28-libsoup-devel is earlier than 0:2.2.98-5.el4.1" test_ref="oval:org.mitre.oval:tst:38001"/>
            <criterion comment="evolution28-libsoup is earlier than 0:2.2.98-5.el4.1" test_ref="oval:org.mitre.oval:tst:38097"/>
            <criterion comment="libsoup-devel is earlier than 0:2.2.1-4.el4.1" test_ref="oval:org.mitre.oval:tst:38304"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libsoup is earlier than 0:2.2.98-2.el5_3.1" test_ref="oval:org.mitre.oval:tst:38189"/>
            <criterion comment="libsoup-devel is earlier than 0:2.2.98-2.el5_3.1" test_ref="oval:org.mitre.oval:tst:38136"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9598" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1469"/>
        <description>Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:11.437-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:53.117-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:57.517-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9598 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:52.826-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:33.238-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9597" version="5" class="vulnerability">
      <metadata>
        <title>PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3660" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3660"/>
        <description>PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:20.548-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:52.368-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:56.743-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9597 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:02.456-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:32.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:38010"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37683"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37468"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37994"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37569"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37746"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38324"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38288"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38029"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:37974"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38154"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38499"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38401"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38018"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38505"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38494"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38075"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38387"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38058"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38147"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38305"/>
            <criterion comment="php-common is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38268"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38298"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37882"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37952"/>
            <criterion comment="php is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38099"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38415"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38511"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38115"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38367"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38569"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38440"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38536"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38507"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38316"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38493"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37667"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9596" version="5" class="vulnerability">
      <metadata>
        <title>zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x before 5.1.3 can cause zend_hash_del to delete the wrong element, which prevents a variable from being unset even when the PHP unset function is called, which might cause the variable's value to be used in security-relevant operations.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0205"/>
        <description>KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:02.551-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:52.167-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:56.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9596 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:25.628-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:31.920-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdenetwork-devel is earlier than 7:3.1.3-1.8" test_ref="oval:org.mitre.oval:tst:31423"/>
          <criterion comment="kdenetwork is earlier than 7:3.1.3-1.8" test_ref="oval:org.mitre.oval:tst:31376"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9595" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0771"/>
        <description>Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:32.334-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:51.903-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:56.336-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9595 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:43.422-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:31.659-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="lha is earlier than 0:1.14i-10.4" test_ref="oval:org.mitre.oval:tst:29793"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9594" version="5" class="vulnerability">
      <metadata>
        <title>The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2464"/>
        <description>The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:25.300-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:51.649-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:56.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9594 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:40.389-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:31.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:38809"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38249"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38575"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38853"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9593" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has previously saved a shortcut.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2810" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2810"/>
        <description>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has previously saved a shortcut.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:35.710-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:51.001-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:55.415-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9593 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:30.638-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:30.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9592" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1036" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1036"/>
        <description>Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:50.850-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:50.814-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:55.221-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9592 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:40.352-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:30.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="squirrelmail is earlier than 0:1.4.3a-7.EL3" test_ref="oval:org.mitre.oval:tst:30184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9591" version="5" class="vulnerability">
      <metadata>
        <title>MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0711"/>
        <description>MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:49.680-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:50.196-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:54.880-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9591 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:06.049-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:29.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:3.23.58-15.RHEL3.1" test_ref="oval:org.mitre.oval:tst:31367"/>
            <criterion comment="mysql-devel is earlier than 0:3.23.58-15.RHEL3.1" test_ref="oval:org.mitre.oval:tst:31299"/>
            <criterion comment="mysql-bench is earlier than 0:3.23.58-15.RHEL3.1" test_ref="oval:org.mitre.oval:tst:31391"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.10a-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:30977"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.10a-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31612"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.10a-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31452"/>
            <criterion comment="mysql-server is earlier than 0:4.1.10a-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31294"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9590" version="5" class="vulnerability">
      <metadata>
        <title>The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0159"/>
        <description>The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:17.168-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:49.635-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:54.363-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9590 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:08.452-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:28.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39910"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40282"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40001"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40160"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39327"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39963"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39749"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40277"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39865"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40145"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40087"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40185"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40258"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40130"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40147"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40264"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9589" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1268"/>
        <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:18.301-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:49.339-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:54.047-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9589 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:49.121-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:28.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-46.2.ent" test_ref="oval:org.mitre.oval:tst:31786"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.46-46.2.ent" test_ref="oval:org.mitre.oval:tst:31975"/>
            <criterion comment="httpd is earlier than 0:2.0.46-46.2.ent" test_ref="oval:org.mitre.oval:tst:31650"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31790"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31890"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31948"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31906"/>
            <criterion comment="httpd is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:32146"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9588" version="5" class="vulnerability">
      <metadata>
        <title>The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0809"/>
        <description>The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:32.057-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:49.134-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:53.796-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9588 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:24.962-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:28.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="httpd-devel is earlier than 0:2.0.46-40.ent" test_ref="oval:org.mitre.oval:tst:30894"/>
          <criterion comment="mod_ssl is earlier than 1:2.0.46-40.ent" test_ref="oval:org.mitre.oval:tst:30928"/>
          <criterion comment="httpd is earlier than 0:2.0.46-40.ent" test_ref="oval:org.mitre.oval:tst:30979"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9587" version="5" class="vulnerability">
      <metadata>
        <title>prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0075"/>
        <description>prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:34.569-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:48.876-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:53.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9587 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:37.565-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:27.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-9.EL3" test_ref="oval:org.mitre.oval:tst:30441"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-9.EL4" test_ref="oval:org.mitre.oval:tst:30956"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9586" version="5" class="vulnerability">
      <metadata>
        <title>The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2697" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2697"/>
        <description>The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:18.677-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:48.677-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:53.350-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9586 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:44.156-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:27.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gdm-docs is earlier than 1:2.16.0-56.el5" test_ref="oval:org.mitre.oval:tst:39109"/>
          <criterion comment="gdm is earlier than 1:2.16.0-56.el5" test_ref="oval:org.mitre.oval:tst:38314"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9585" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka "the second issue."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1186"/>
        <description>Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka "the second issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:21.230-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:48.355-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:52.955-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36267"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36295"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35708"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35618"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36334"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36509"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35698"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35872"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35719"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36068"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36582"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36568"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9584" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1153" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1153"/>
        <description>Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:31.405-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:47.790-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:52.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9584 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:54.928-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:26.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31478"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31488"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31751"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31647"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30850"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31749"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31658"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31636"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31780"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30828"/>
            <criterion comment="firefox is earlier than 0:1.0.3-1.4.1" test_ref="oval:org.mitre.oval:tst:31646"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31716"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31758"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9583" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (Alphas_Of_Color), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3662"/>
        <description>Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (Alphas_Of_Color), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:20.145-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:47.584-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:52.240-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9583 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:38.160-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:26.391-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="netpbm is earlier than 0:9.24-11.30.4" test_ref="oval:org.mitre.oval:tst:32233"/>
          <criterion comment="netpbm-progs is earlier than 0:9.24-11.30.4" test_ref="oval:org.mitre.oval:tst:32304"/>
          <criterion comment="netpbm-devel is earlier than 0:9.24-11.30.4" test_ref="oval:org.mitre.oval:tst:32108"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9582" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1189"/>
        <description>Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:22.184-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:46.909-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:51.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36548"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36455"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36422"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36295"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36406"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36334"/>
            <criterion comment="java-1.5.0-ibm is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36155"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36267"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35708"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35618"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36613"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36614"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36509"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36558"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36485"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35872"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36582"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36555"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36414"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36622"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36688"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36265"/>
            <criterion comment="java-1.6.0-ibm is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36319"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36706"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36205"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36535"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36515"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36523"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36323"/>
            <criterion comment="java-1.5.0-ibm is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35890"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35698"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35719"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36340"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36068"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36568"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9581" version="5" class="vulnerability">
      <metadata>
        <title>Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0184"/>
        <description>Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:30.749-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:46.713-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:51.203-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9581 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:53.427-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:26.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="libpcap is earlier than 14:0.7.2-7.E3.2" test_ref="oval:org.mitre.oval:tst:30722"/>
          <criterion comment="tcpdump is earlier than 14:3.7.2-7.E3.2" test_ref="oval:org.mitre.oval:tst:29722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9580" version="5" class="vulnerability">
      <metadata>
        <title>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0112"/>
        <description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:42.370-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:46.500-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:50.918-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9580 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:40.839-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:25.766-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.4" test_ref="oval:org.mitre.oval:tst:30638"/>
          <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.4" test_ref="oval:org.mitre.oval:tst:30381"/>
          <criterion comment="openssl is earlier than 0:0.9.7a-33.4" test_ref="oval:org.mitre.oval:tst:30673"/>
          <criterion comment="openssl096b is earlier than 0:0.9.6b-16" test_ref="oval:org.mitre.oval:tst:30479"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9579" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1455" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1455"/>
        <description>Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:40.137-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:46.138-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:50.652-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9579 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:47.620-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:25.380-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="freeradius is earlier than 0:1.0.1-1.1.RHEL3" test_ref="oval:org.mitre.oval:tst:31698"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:32002"/>
            <criterion comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31962"/>
            <criterion comment="freeradius is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31992"/>
            <criterion comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9578" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0147"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:27.948-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:45.798-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:50.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9578 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:59.259-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:24.918-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:30819"/>
          <criterion comment="mozilla is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31515"/>
          <criterion comment="mozilla-chat is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31278"/>
          <criterion comment="mozilla-mail is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31465"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31606"/>
          <criterion comment="mozilla-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31480"/>
          <criterion comment="mozilla-nss is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31417"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31313"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31469"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31598"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9577" version="5" class="vulnerability">
      <metadata>
        <title>The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2364"/>
        <description>The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:05.981-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:45.435-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:49.913-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9577 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:58.410-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:24.353-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:37941"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:37561"/>
            <criterion comment="httpd is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:37595"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37897"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37670"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37862"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37679"/>
            <criterion comment="httpd is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37575"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:37895"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:37730"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:36990"/>
            <criterion comment="httpd is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:37803"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9576" version="5" class="vulnerability">
      <metadata>
        <title>qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/args temporary file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4993"/>
        <description>qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/args temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:30.004-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:45.223-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:49.693-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9576 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:10.953-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:23.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="xen-libs is earlier than 0:3.0.3-64.el5_2.9" test_ref="oval:org.mitre.oval:tst:38117"/>
          <criterion comment="xen is earlier than 0:3.0.3-64.el5_2.9" test_ref="oval:org.mitre.oval:tst:37962"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-64.el5_2.9" test_ref="oval:org.mitre.oval:tst:38017"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9575" version="5" class="vulnerability">
      <metadata>
        <title>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625"/>
        <description>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:39.436-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:44.686-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:49.193-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9575 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:52.294-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:23.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32437"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32206"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:31553"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32284"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.4" test_ref="oval:org.mitre.oval:tst:32545"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32254"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32499"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9574" version="5" class="vulnerability">
      <metadata>
        <title>The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create network amplification between two routers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2242"/>
        <description>The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create network amplification between two routers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:02.198-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:44.371-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:48.843-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9574 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:54.308-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:22.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34146"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34219"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34205"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:33862"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34224"/>
          <criterion comment="kernel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:33837"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34231"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34073"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:33861"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:33594"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.4.el5" test_ref="oval:org.mitre.oval:tst:34059"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9573" version="5" class="vulnerability">
      <metadata>
        <title>Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0211"/>
        <description>Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:54.309-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:44.153-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:48.601-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9573 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:33.641-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:22.498-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" test_ref="oval:org.mitre.oval:tst:30954"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" test_ref="oval:org.mitre.oval:tst:31281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9572" version="5" class="vulnerability">
      <metadata>
        <title>The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2120"/>
        <description>The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:30.281-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:43.884-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:48.350-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9572 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:43.980-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:22.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32689"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32435"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32329"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9571" version="5" class="vulnerability">
      <metadata>
        <title>VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1138"/>
        <description>VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:07.405-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:43.574-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:47.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9571 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:25.659-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:21.620-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:30321"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:31244"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:30519"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:30858"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:31167"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31180"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31161"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31316"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31312"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31163"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9570" version="5" class="vulnerability">
      <metadata>
        <title>The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3443" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3443"/>
        <description>The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:01.689-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:43.069-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:47.463-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9570 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:04.805-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:20.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37606"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37736"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37427"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37760"/>
            <criterion comment="ruby is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37497"/>
            <criterion comment="irb is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37751"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:36770"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37462"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37630"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36810"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36902"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37678"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37674"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37720"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37735"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37344"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37697"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37273"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37563"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37438"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37757"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37463"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37172"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9569" version="5" class="vulnerability">
      <metadata>
        <title>Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2498" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2498"/>
        <description>Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:49.732-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:42.575-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:46.934-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9569 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:29.809-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:20.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:31517"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:32191"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:32009"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:31823"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:31971"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:32008"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:31197"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32052"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31200"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31503"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32192"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31957"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31771"/>
            <criterion comment="php is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31974"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31734"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32178"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31386"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32029"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31677"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32000"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32062"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9568" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are returned by the getConfigurations function, aka Bug Id 6822057.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3879" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3879"/>
        <description>Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are returned by the getConfigurations function, aka Bug Id 6822057.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:45.816-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:42.339-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:46.687-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9568 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:24.353-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:19.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:38878"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39616"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39115"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39531"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39655"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9567" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1235"/>
        <description>Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:47.444-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:41.914-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:46.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9567 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:18.946-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:19.373-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31090"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31317"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31165"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31297"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31259"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:30906"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31029"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31014"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:30920"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9566" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0457"/>
        <description>Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:19.941-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:41.637-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:45.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9566 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:34.487-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:18.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9565" version="3" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3104"/>
        <description>Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:51.594-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:41.242-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:45.534-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37481"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36778"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37475"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37445"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37487"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.16-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:37483"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36649"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37229"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37509"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37426"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37368"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37035"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37181"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37441"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37315"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37359"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37490"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.16-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:37461"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9564" version="5" class="vulnerability">
      <metadata>
        <title>The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4377"/>
        <description>The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:01.901-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:40.893-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:45.228-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9564 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:54.068-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:18.464-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9563" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.18, and possibly other versions, when running on AMD64 architectures, allows local users to cause a denial of service (crash) via certain ptrace calls.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1615"/>
        <description>Linux kernel 2.6.18, and possibly other versions, when running on AMD64 architectures, allows local users to cause a denial of service (crash) via certain ptrace calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:38.739-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:40.408-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:44.670-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9563 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:14.697-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:17.741-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36201"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36534"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36373"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36702"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36615"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36490"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36370"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35738"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36249"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36731"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35733"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36697"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36610"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36727"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:35799"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:35977"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36772"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36502"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36670"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36665"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:35765"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36539"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9562" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0384"/>
        <description>Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:47.619-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:39.963-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:44.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9562 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:44.513-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:17.100-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9561" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in Linux kernel before 2.6.13.2 allow local users to cause a denial of service (kernel OOPS from null dereference) via (1) fput in a 32-bit ioctl on 64-bit x86 systems or (2) sockfd_put in the 32-bit routing_ioctl function on 64-bit systems.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3044"/>
        <description>Multiple vulnerabilities in Linux kernel before 2.6.13.2 allow local users to cause a denial of service (kernel OOPS from null dereference) via (1) fput in a 32-bit ioctl on 64-bit x86 systems or (2) sockfd_put in the 32-bit routing_ioctl function on 64-bit systems.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:59.818-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:39.578-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:43.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9561 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:27.712-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:16.521-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9560" version="5" class="vulnerability">
      <metadata>
        <title>The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0001"/>
        <description>The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:16.128-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:39.301-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:43.545-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9560 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:13.741-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:15.973-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33775"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33751"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33264"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33777"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33668"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33639"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33564"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33538"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9559" version="5" class="vulnerability">
      <metadata>
        <title>MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2691"/>
        <description>MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:14.656-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:38.952-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:43.233-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9559 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:21.778-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:15.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37045"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37456"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:36967"/>
            <criterion comment="mysql-server is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37224"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36197"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36749"/>
            <criterion comment="mysql-test is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36750"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36831"/>
            <criterion comment="mysql-server is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9558" version="5" class="vulnerability">
      <metadata>
        <title>The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5029"/>
        <description>The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:30.060-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:38.331-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:42.544-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9558 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:13.538-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:14.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37830"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37968"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37984"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37633"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37352"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38043"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37989"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37908"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37748"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37825"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38002"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38161"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:37996"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38259"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:37366"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:37939"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38003"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38294"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38054"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:37318"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38086"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38226"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38094"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9557" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0411"/>
        <description>Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:43.242-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:37.939-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:42.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9557 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:24.577-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:14.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="hpijs is earlier than 0:1.3-32.1.13" test_ref="oval:org.mitre.oval:tst:36464"/>
            <criterion comment="ghostscript-devel is earlier than 0:7.05-32.1.13" test_ref="oval:org.mitre.oval:tst:36326"/>
            <criterion comment="ghostscript is earlier than 0:7.05-32.1.13" test_ref="oval:org.mitre.oval:tst:36149"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_6.1" test_ref="oval:org.mitre.oval:tst:36082"/>
            <criterion comment="ghostscript is earlier than 0:7.07-33.2.el4_6.1" test_ref="oval:org.mitre.oval:tst:35551"/>
            <criterion comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_6.1" test_ref="oval:org.mitre.oval:tst:36061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:8.15.2-9.1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36325"/>
            <criterion comment="ghostscript is earlier than 0:8.15.2-9.1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35805"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.15.2-9.1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36363"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9556" version="5" class="vulnerability">
      <metadata>
        <title>A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and send requests to OpenPegasus WBEM services.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4313"/>
        <description>A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and send requests to OpenPegasus WBEM services.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:45.429-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:37.738-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:41.964-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9556 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:11.955-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:13.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="tog-pegasus is earlier than 2:2.7.0-2.el5_2.1" test_ref="oval:org.mitre.oval:tst:38022"/>
          <criterion comment="tog-pegasus-devel is earlier than 2:2.7.0-2.el5_2.1" test_ref="oval:org.mitre.oval:tst:38089"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9555" version="5" class="vulnerability">
      <metadata>
        <title>arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an invalid dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1514" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1514"/>
        <description>arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an invalid dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:08.201-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:37.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:41.604-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9555 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:31.900-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:13.372-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37470"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37734"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37826"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37656"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37782"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37432"/>
          <criterion comment="kernel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37747"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37811"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37951"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37485"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9554" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel before 2.6.18, when running on x86_64 systems, does not properly save or restore EFLAGS during a context switch, which allows local users to cause a denial of service (crash) by causing SYSENTER to set an NT flag, which can trigger a crash on the IRET of the next task.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5755"/>
        <description>Linux kernel before 2.6.18, when running on x86_64 systems, does not properly save or restore EFLAGS during a context switch, which allows local users to cause a denial of service (crash) by causing SYSENTER to set an NT flag, which can trigger a crash on the IRET of the next task.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:09.838-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:37.115-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:41.171-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9554 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:54.093-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:12.904-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37778"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37855"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37870"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37881"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37504"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37738"/>
          <criterion comment="kernel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37774"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37247"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37715"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37954"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37668"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37947"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9553" version="5" class="vulnerability">
      <metadata>
        <title>Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2549"/>
        <description>Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:47.863-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:36.838-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:40.846-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9553 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:03.212-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:12.531-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:1.4.5-16" test_ref="oval:org.mitre.oval:tst:31035"/>
            <criterion comment="evolution-devel is earlier than 0:1.4.5-16" test_ref="oval:org.mitre.oval:tst:31372"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:2.0.2-16.3" test_ref="oval:org.mitre.oval:tst:31247"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-16.3" test_ref="oval:org.mitre.oval:tst:31492"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9552" version="5" class="vulnerability">
      <metadata>
        <title>The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.12, and 2.4 before 2.4.29, does not properly verify the ndigis argument for a new route, which allows attackers to trigger array out-of-bounds errors with a large number of digipeats.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3273" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3273"/>
        <description>The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.12, and 2.4 before 2.4.29, does not properly verify the ndigis argument for a new route, which allows attackers to trigger array out-of-bounds errors with a large number of digipeats.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:07.150-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:36.562-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:40.554-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9552 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:09:03.505-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:12.163-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
          <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9551" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1234"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:45.945-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:35.820-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:39.654-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9551 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:17.482-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:11.414-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9550" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability than CVE-2004-1481.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2629" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2629"/>
        <description>Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability than CVE-2004-1481.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:34.078-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:35.629-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:39.458-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9550 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:34.968-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:11.126-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.1" test_ref="oval:org.mitre.oval:tst:31952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9549" version="5" class="vulnerability">
      <metadata>
        <title>Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3385"/>
        <description>Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:04.737-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:35.324-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:39.147-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9549 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:26.229-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:10.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:35173"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:35009"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:34829"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:34843"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:35076"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:34950"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:35160"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:34831"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:35047"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:34953"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.3.0.2.el5" test_ref="oval:org.mitre.oval:tst:35000"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9548" version="5" class="vulnerability">
      <metadata>
        <title>Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier, which is processed by certain web browsers including Internet Explorer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0195"/>
        <description>Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier, which is processed by certain web browsers including Internet Explorer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:36.246-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:35.106-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:38.852-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9548 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:18.503-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:10.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.6-5.el3" test_ref="oval:org.mitre.oval:tst:32265"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.6-5.el4" test_ref="oval:org.mitre.oval:tst:32721"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9547" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2870"/>
        <description>Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:43.525-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:34.479-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:38.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9547 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:37.382-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:09.540-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34409"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34257"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34432"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33988"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33721"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33693"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34313"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34281"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33894"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34228"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:33625"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33931"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34334"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34021"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34249"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:34293"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.1.el4" test_ref="oval:org.mitre.oval:tst:34371"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34446"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34262"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34366"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33994"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34322"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34445"/>
            <criterion comment="yelp is earlier than 0:2.16.0-15.el5" test_ref="oval:org.mitre.oval:tst:33445"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34323"/>
            <criterion comment="devhelp is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34204"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34162"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9546" version="3" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote attackers to modify HTTP headers for client requests and conduct HTTP Request Splitting attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6245"/>
        <description>Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote attackers to modify HTTP headers for client requests and conduct HTTP Request Splitting attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:21.229-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:34.236-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:37.975-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criterion comment="flash-plugin is earlier than 0:9.0.115.0-1.el3.with.oss" test_ref="oval:org.mitre.oval:tst:35926"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criterion comment="flash-plugin is earlier than 0:9.0.115.0-1.el4" test_ref="oval:org.mitre.oval:tst:35400"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criterion comment="flash-plugin is earlier than 0:9.0.115.0-1.el5" test_ref="oval:org.mitre.oval:tst:35776"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9545" version="5" class="vulnerability">
      <metadata>
        <title>lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1269"/>
        <description>lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:18.233-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:33.926-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:37.699-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9545 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:25.465-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:09.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.22" test_ref="oval:org.mitre.oval:tst:30882"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.22" test_ref="oval:org.mitre.oval:tst:31108"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.22" test_ref="oval:org.mitre.oval:tst:31170"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:30919"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31056"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31093"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9544" version="5" class="vulnerability">
      <metadata>
        <title>Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1269"/>
        <description>Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:35.089-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:33.706-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:37.471-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9544 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:53.391-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:08.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el3" test_ref="oval:org.mitre.oval:tst:31762"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el4" test_ref="oval:org.mitre.oval:tst:31939"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9543" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0142"/>
        <description>Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:26.755-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:33.212-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:36.927-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9543 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:56.986-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:08.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30665"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31499"/>
            <criterion comment="mozilla is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31604"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31381"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31622"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30651"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31560"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31110"/>
            <criterion comment="evolution is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31003"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31404"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31375"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31106"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31418"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9542" version="3" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to cause a denial of service (crash) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1194" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1194"/>
        <description>Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to cause a denial of service (crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:06.995-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:32.348-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:36.099-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36548"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36455"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36295"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36334"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36614"/>
            <criterion comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36678"/>
            <criterion comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36732"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36422"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36406"/>
            <criterion comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36696"/>
            <criterion comment="java-1.5.0-ibm is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36155"/>
            <criterion comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36210"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36267"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35708"/>
            <criterion comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36565"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36613"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35618"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36509"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36558"/>
            <criterion comment="java-1.6.0-bea-src is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36590"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36555"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36414"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36622"/>
            <criterion comment="java-1.6.0-ibm is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36319"/>
            <criterion comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36686"/>
            <criterion comment="java-1.6.0-bea-devel is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36423"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36535"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36515"/>
            <criterion comment="java-1.6.0-bea-missioncontrol is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36683"/>
            <criterion comment="java-1.6.0-bea-demo is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36331"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36323"/>
            <criterion comment="java-1.5.0-ibm is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35890"/>
            <criterion comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36343"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35719"/>
            <criterion comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36079"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36340"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36485"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35872"/>
            <criterion comment="java-1.6.0-bea is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36195"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36582"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36265"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36688"/>
            <criterion comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36494"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36706"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36205"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36523"/>
            <criterion comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36580"/>
            <criterion comment="java-1.5.0-bea-missioncontrol is earlier than 0:1.5.0.14-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36047"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35698"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36068"/>
            <criterion comment="java-1.6.0-bea-jdbc is earlier than 1:1.6.0.03-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36658"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36568"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9541" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0689"/>
        <description>Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:25.089-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:32.057-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:35.730-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9541 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:03.422-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:07.632-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="kdelibs is earlier than 6:3.3.1-17.el4_8.1" test_ref="oval:org.mitre.oval:tst:39402"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-17.el4_8.1" test_ref="oval:org.mitre.oval:tst:39743"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-25.el5_4.1" test_ref="oval:org.mitre.oval:tst:39677"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-25.el5_4.1" test_ref="oval:org.mitre.oval:tst:38993"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-25.el5_4.1" test_ref="oval:org.mitre.oval:tst:39605"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9540" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first.  NOTE: this issue is due to an incorrect patch for CVE-2007-5378.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5137" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5137"/>
        <description>Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first.  NOTE: this issue is due to an incorrect patch for CVE-2007-5378.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:50.476-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:31.822-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:35.524-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9540 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:40.619-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:07.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="tk-devel is earlier than 0:8.4.13-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:36375"/>
          <criterion comment="tk is earlier than 0:8.4.13-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:35860"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:954" version="2" class="vulnerability">
      <metadata>
        <title>Konqueror URI Handler "-" Filter Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0411"/>
        <description>The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:54.899-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.684-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdelibs version is less than 3.1.3-6.4" negate="false" test_ref="oval:org.mitre.oval:tst:1426"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="telnet, rlogin, ssh or kmail is executable">
            <criteria operator="OR" comment="/usr/bin/telnet is executable">
              <criterion comment="/usr/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1425"/>
              <criterion comment="/usr/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1424"/>
              <criterion comment="/usr/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1423"/>
            </criteria>
            <criteria operator="OR" comment="/usr/kerberos/bin/telnet is executable">
              <criterion comment="/usr/kerberos/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1422"/>
              <criterion comment="/usr/kerberos/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1421"/>
              <criterion comment="/usr/kerberos/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1420"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rlogin is executable">
              <criterion comment="/usr/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1419"/>
              <criterion comment="/usr/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1418"/>
              <criterion comment="/usr/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1417"/>
            </criteria>
            <criteria operator="OR" comment="/usr/kerberos/bin/rlogin is executable">
              <criterion comment="/usr/kerberos/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1416"/>
              <criterion comment="/usr/kerberos/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1415"/>
              <criterion comment="/usr/kerberos/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1414"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ssh is executable">
              <criterion comment="/usr/bin/ssh is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1413"/>
              <criterion comment="/usr/bin/ssh is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1412"/>
              <criterion comment="/usr/bin/ssh is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1411"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/kmail is executable">
              <criterion comment="/usr/bin/kmail is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1410"/>
              <criterion comment="/usr/bin/kmail is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1409"/>
              <criterion comment="/usr/bin/kmail is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1408"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9539" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5000" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5000"/>
        <description>Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:15.632-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:31.458-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:35.154-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9539 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:50.570-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:06.763-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-70.ent" test_ref="oval:org.mitre.oval:tst:35773"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-70.ent" test_ref="oval:org.mitre.oval:tst:36016"/>
            <criterion comment="httpd is earlier than 0:2.0.46-70.ent" test_ref="oval:org.mitre.oval:tst:35281"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35606"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35973"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35916"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35852"/>
            <criterion comment="httpd is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35768"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-11.el5_1.3" test_ref="oval:org.mitre.oval:tst:35953"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-11.el5_1.3" test_ref="oval:org.mitre.oval:tst:35668"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-11.el5_1.3" test_ref="oval:org.mitre.oval:tst:35991"/>
            <criterion comment="httpd is earlier than 0:2.2.3-11.el5_1.3" test_ref="oval:org.mitre.oval:tst:35696"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9538" version="5" class="vulnerability">
      <metadata>
        <title>slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2499" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2499"/>
        <description>slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:06.098-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:31.237-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:34.882-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9538 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:00.149-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:06.406-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="slocate is earlier than 0:2.7-3.RHEL3.6" test_ref="oval:org.mitre.oval:tst:31533"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="slocate is earlier than 0:2.7-13.el4.6" test_ref="oval:org.mitre.oval:tst:31470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9537" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal) 0.10.11 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5469"/>
        <description>Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal) 0.10.11 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:11.323-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:30.958-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:34.630-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9537 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:58.000-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:05.809-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33205"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33170"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:32550"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:33152"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9536" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3608" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3608"/>
        <description>Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:42.153-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:30.515-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:34.181-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9536 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:38.769-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:05.213-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39438"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_8.5" test_ref="oval:org.mitre.oval:tst:39221"/>
            <criterion comment="xpdf is earlier than 1:3.00-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:38963"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39062"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:39430"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39529"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39290"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:38854"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39346"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39383"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:38836"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:39511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9535" version="5" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1304"/>
        <description>The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:57.773-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:30.260-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:33.861-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9535 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:45.867-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:04.698-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9534" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1464"/>
        <description>Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:29.313-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:29.978-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:33.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9534 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:55.829-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:04.330-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9533" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0593" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0593"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:32.456-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:29.655-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:33.267-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9533 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:38.233-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:03.820-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9532" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1852" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1852"/>
        <description>Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:24.195-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:29.448-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:33.041-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9532 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:15.881-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:03.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdenetwork-nowlistening is earlier than 7:3.3.1-2.3" test_ref="oval:org.mitre.oval:tst:32125"/>
          <criterion comment="kdenetwork-devel is earlier than 7:3.3.1-2.3" test_ref="oval:org.mitre.oval:tst:32141"/>
          <criterion comment="kdenetwork is earlier than 7:3.3.1-2.3" test_ref="oval:org.mitre.oval:tst:31965"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9531" version="5" class="vulnerability">
      <metadata>
        <title>Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2274"/>
        <description>Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:59.601-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:29.170-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:32.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9531 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:57.455-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:03.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9530" version="5" class="vulnerability">
      <metadata>
        <title>MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1420"/>
        <description>MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:09.893-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:28.887-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:32.486-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9530 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:12.569-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:02.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36197"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36749"/>
          <criterion comment="mysql-test is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36750"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36831"/>
          <criterion comment="mysql-server is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36646"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9529" version="5" class="vulnerability">
      <metadata>
        <title>The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4059"/>
        <description>The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:59.233-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:28.415-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:31.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9529 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:51.964-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:02.102-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9528" version="5" class="vulnerability">
      <metadata>
        <title>Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3.  NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie.  Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability.  NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4253" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4253"/>
        <description>Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3.  NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie.  Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability.  NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:19.553-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:27.878-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:31.461-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9528 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:01.521-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:01.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32910"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9527" version="5" class="vulnerability">
      <metadata>
        <title>drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4138"/>
        <description>drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:26.880-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:27.564-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:31.088-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9527 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:17.848-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:00.924-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40050"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39464"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39090"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40063"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39443"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39703"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39080"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39862"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40057"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40029"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39849"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40039"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9526" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1210"/>
        <description>Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:36.890-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:27.268-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:30.654-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9526 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:58.883-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:00.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:38258"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:38534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38635"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38709"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38670"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9525" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1633" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1633"/>
        <description>Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:13.439-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:26.737-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:30.174-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9525 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:07.731-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:59.780-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38877"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38938"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39012"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39048"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38799"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39160"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39030"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38637"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38231"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39133"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38985"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:37971"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38820"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38641"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38838"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38699"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38813"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38840"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38890"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38529"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38350"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38066"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38388"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9524" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in cluster/cman/daemon/daemon.c in cman (redhat-cluster-suite) before 20070622 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long client messages.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3374"/>
        <description>Buffer overflow in cluster/cman/daemon/daemon.c in cman (redhat-cluster-suite) before 20070622 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long client messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:13.948-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:26.538-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:29.927-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9524 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:49:50.705-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:59.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="cman-devel is earlier than 0:2.0.64-1.0.1.el5" test_ref="oval:org.mitre.oval:tst:34743"/>
          <criterion comment="cman is earlier than 0:2.0.64-1.0.1.el5" test_ref="oval:org.mitre.oval:tst:34252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9523" version="5" class="vulnerability">
      <metadata>
        <title>The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0968" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0968"/>
        <description>The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:43.499-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:26.269-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:29.651-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9523 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:15.719-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:59.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="glibc is earlier than 0:2.3.2-95.30" test_ref="oval:org.mitre.oval:tst:30926"/>
          <criterion comment="glibc-utils is earlier than 0:2.3.2-95.30" test_ref="oval:org.mitre.oval:tst:30313"/>
          <criterion comment="glibc-devel is earlier than 0:2.3.2-95.30" test_ref="oval:org.mitre.oval:tst:31018"/>
          <criterion comment="nptl-devel is earlier than 0:2.3.2-95.30" test_ref="oval:org.mitre.oval:tst:31055"/>
          <criterion comment="nscd is earlier than 0:2.3.2-95.30" test_ref="oval:org.mitre.oval:tst:30469"/>
          <criterion comment="glibc-profile is earlier than 0:2.3.2-95.30" test_ref="oval:org.mitre.oval:tst:31102"/>
          <criterion comment="glibc-common is earlier than 0:2.3.2-95.30" test_ref="oval:org.mitre.oval:tst:30967"/>
          <criterion comment="glibc-headers is earlier than 0:2.3.2-95.30" test_ref="oval:org.mitre.oval:tst:31074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9522" version="5" class="vulnerability">
      <metadata>
        <title>sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1760"/>
        <description>sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:19.772-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:26.010-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:29.425-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9522 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:56.532-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:58.756-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="sysreport is earlier than 0:1.3.7.2-6" test_ref="oval:org.mitre.oval:tst:31795"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="sysreport is earlier than 0:1.3.15-2" test_ref="oval:org.mitre.oval:tst:31426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9521" version="5" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0010"/>
        <description>Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:25.192-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:25.685-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:29.169-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9521 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:32.845-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:57.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31265"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31097"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9520" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame.  NOTE: this was originally referred to as heap-based, but it might be stack-based.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1218"/>
        <description>Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame.  NOTE: this was originally referred to as heap-based, but it might be stack-based.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:12.310-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:25.408-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:28.833-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9520 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:26.881-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:57.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-12.el4" test_ref="oval:org.mitre.oval:tst:34426"/>
            <criterion comment="libpcap is earlier than 14:0.8.3-12.el4" test_ref="oval:org.mitre.oval:tst:34317"/>
            <criterion comment="tcpdump is earlier than 14:3.8.2-12.el4" test_ref="oval:org.mitre.oval:tst:33439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-18.el5" test_ref="oval:org.mitre.oval:tst:34286"/>
            <criterion comment="libpcap-devel is earlier than 14:0.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:34191"/>
            <criterion comment="libpcap is earlier than 14:0.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:34045"/>
            <criterion comment="tcpdump is earlier than 14:3.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:33937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9519" version="5" class="vulnerability">
      <metadata>
        <title>The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1949"/>
        <description>The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:57.771-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:24.801-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:28.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9519 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:43.243-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:56.991-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnutls is earlier than 0:1.0.20-4.el4_6" test_ref="oval:org.mitre.oval:tst:36194"/>
            <criterion comment="gnutls-devel is earlier than 0:1.0.20-4.el4_6" test_ref="oval:org.mitre.oval:tst:36609"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnutls is earlier than 0:1.4.1-3.el5_1" test_ref="oval:org.mitre.oval:tst:36294"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-3.el5_1" test_ref="oval:org.mitre.oval:tst:35940"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-3.el5_1" test_ref="oval:org.mitre.oval:tst:36811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9516" version="5" class="vulnerability">
      <metadata>
        <title>mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3081"/>
        <description>mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:20.992-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:24.580-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:28.340-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9516 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:59.958-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:56.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32252"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32551"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32245"/>
          <criterion comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32560"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9515" version="5" class="vulnerability">
      <metadata>
        <title>The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3083"/>
        <description>The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:09.828-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:24.339-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:28.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9515 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:47.326-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:56.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="krb5-workstation is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32665"/>
          <criterion comment="krb5 is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32887"/>
          <criterion comment="krb5-libs is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32980"/>
          <criterion comment="krb5-server is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32772"/>
          <criterion comment="krb5-devel is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32806"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9514" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0910"/>
        <description>Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:55.962-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:23.592-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:27.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9514 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:50.992-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:55.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9513" version="5" class="vulnerability">
      <metadata>
        <title>The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1883" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1883"/>
        <description>The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:50.899-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:23.283-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:26.954-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9513 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:59.557-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:54.820-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39101"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39357"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38568"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39331"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39316"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39054"/>
          <criterion comment="kernel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39274"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39407"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39435"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39442"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38473"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9512" version="5" class="vulnerability">
      <metadata>
        <title>The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0003"/>
        <description>The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:50.777-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:22.959-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:26.660-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9512 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:05.481-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:54.460-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31090"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31317"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31165"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31297"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31259"/>
          <criterion comment="kernel is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:30906"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31029"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31014"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:30920"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9511" version="5" class="vulnerability">
      <metadata>
        <title>fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4210"/>
        <description>fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:28.578-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:22.355-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:25.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9511 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:05.196-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:53.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37931"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37846"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37817"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37663"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37799"/>
            <criterion comment="kernel is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37028"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37885"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37981"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37117"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37470"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37734"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37826"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37656"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37782"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37432"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37747"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37811"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37951"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37485"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37778"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37855"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37870"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37881"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37504"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37738"/>
            <criterion comment="kernel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37774"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37247"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37715"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37954"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37668"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37947"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9510" version="5" class="vulnerability">
      <metadata>
        <title>SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1858" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1858"/>
        <description>SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:18.520-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:21.998-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:25.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9510 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:40.120-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:53.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32576"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32814"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32958"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32801"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32865"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32880"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32747"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32200"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32838"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9509" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1766"/>
        <description>Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:14.265-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:21.815-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:25.400-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9509 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:30.134-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:52.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.5-0.EL4.1" test_ref="oval:org.mitre.oval:tst:31840"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9508" version="5" class="vulnerability">
      <metadata>
        <title>Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0747"/>
        <description>Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:34.261-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:21.548-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:25.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9508 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:13.977-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:52.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-4.0.rhel3.2" test_ref="oval:org.mitre.oval:tst:32599"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-4.0.rhel3.2" test_ref="oval:org.mitre.oval:tst:32616"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32106"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32605"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32417"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9507" version="5" class="vulnerability">
      <metadata>
        <title>The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6725"/>
        <description>The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:32.649-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:21.152-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:24.739-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9507 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:15.502-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:51.983-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="hpijs is earlier than 0:7.05-32.1.20" test_ref="oval:org.mitre.oval:tst:38025"/>
            <criterion comment="ghostscript-devel is earlier than 0:7.05-32.1.20" test_ref="oval:org.mitre.oval:tst:38598"/>
            <criterion comment="ghostscript is earlier than 0:7.05-32.1.20" test_ref="oval:org.mitre.oval:tst:38506"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_7.8" test_ref="oval:org.mitre.oval:tst:38482"/>
            <criterion comment="ghostscript is earlier than 0:7.07-33.2.el4_7.8" test_ref="oval:org.mitre.oval:tst:38656"/>
            <criterion comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_7.8" test_ref="oval:org.mitre.oval:tst:38408"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:38588"/>
            <criterion comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:38629"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:38457"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9506" version="5" class="vulnerability">
      <metadata>
        <title>libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663"/>
        <description>libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:24.099-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:20.810-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:24.423-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9506 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:06.388-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:51.508-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-11.el3" test_ref="oval:org.mitre.oval:tst:39170"/>
            <criterion comment="libvorbis is earlier than 1:1.0-11.el3" test_ref="oval:org.mitre.oval:tst:38631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:38645"/>
            <criterion comment="libvorbis is earlier than 1:1.1.0-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:38909"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_3.3" test_ref="oval:org.mitre.oval:tst:39192"/>
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5_3.3" test_ref="oval:org.mitre.oval:tst:39166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9504" version="5" class="vulnerability">
      <metadata>
        <title>mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1636" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1636"/>
        <description>mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:59.395-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:20.585-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:24.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9504 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:50.644-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:51.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:4.1.12-3.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32079"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.12-3.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31928"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.12-3.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31694"/>
          <criterion comment="mysql-server is earlier than 0:4.1.12-3.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32027"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9503" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3186"/>
        <description>Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:47.594-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:20.287-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:23.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9503 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:54.942-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:50.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32203"/>
            <criterion comment="gtk2 is earlier than 0:2.2.4-19" test_ref="oval:org.mitre.oval:tst:32214"/>
            <criterion comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32393"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32388"/>
            <criterion comment="gtk2-devel is earlier than 0:2.2.4-19" test_ref="oval:org.mitre.oval:tst:32156"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32239"/>
            <criterion comment="gtk2 is earlier than 0:2.4.13-18" test_ref="oval:org.mitre.oval:tst:32313"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32331"/>
            <criterion comment="gtk2-devel is earlier than 0:2.4.13-18" test_ref="oval:org.mitre.oval:tst:32250"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9502" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0174"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:10.285-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:19.747-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:22.915-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9502 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:17.964-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:49.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39934"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40184"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40133"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39775"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40360"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40059"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39946"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40114"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.19-1.el4" test_ref="oval:org.mitre.oval:tst:40284"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40081"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40250"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40304"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40345"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40183"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:39945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40265"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:39621"/>
            <criterion comment="firefox is earlier than 0:3.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40064"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9501" version="5" class="vulnerability">
      <metadata>
        <title>The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1392" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392"/>
        <description>The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:04.877-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:19.237-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:22.404-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9501 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:49.536-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:49.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38336"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38452"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38736"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38742"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38069"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38264"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38724"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38791"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38432"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:37902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38793"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38213"/>
            <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38531"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38828"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38655"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9500" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1420"/>
        <description>Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:24.692-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:18.881-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:22.091-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9500 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:20.632-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:48.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36659"/>
            <criterion comment="libvorbis is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36699"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36519"/>
            <criterion comment="libvorbis is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36387"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36439"/>
            <criterion comment="libvorbis is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36710"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9499" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0663"/>
        <description>Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:16.764-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:18.692-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:21.856-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9499 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:45.364-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:48.489-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criterion comment="perl-DBD-Pg is earlier than 0:1.49-2.el5_3.1" test_ref="oval:org.mitre.oval:tst:38484"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9497" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2472"/>
        <description>Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:18.902-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:18.435-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:21.593-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9497 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:56.590-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:48.085-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:38809"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38249"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38575"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38853"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9496" version="5" class="vulnerability">
      <metadata>
        <title>KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0062" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0062"/>
        <description>KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:21.128-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:17.980-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:21.180-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9496 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:20.416-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:47.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36272"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36493"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36531"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36304"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36522"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36541"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36418"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36371"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36482"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36318"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36285"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36069"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36233"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36199"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9495" version="5" class="vulnerability">
      <metadata>
        <title>rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0426"/>
        <description>rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:01.941-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:17.798-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:20.959-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9495 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:30.307-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:47.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="rsync is earlier than 0:2.5.7-4.3E" test_ref="oval:org.mitre.oval:tst:30539"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9494" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1309"/>
        <description>Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:18.740-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:17.298-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:20.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9494 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:22.323-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:46.453-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38597"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38375"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38403"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38521"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38542"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:37726"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38677"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38096"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38577"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38540"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38634"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38697"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38716"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38190"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38685"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38596"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9493" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3844"/>
        <description>Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:31.463-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:16.726-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:19.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9493 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:38.382-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:45.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35512"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35540"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35394"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35541"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35553"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35552"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:34924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35155"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35489"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35324"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" test_ref="oval:org.mitre.oval:tst:35240"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35182"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35311"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35454"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.7.el4" test_ref="oval:org.mitre.oval:tst:35398"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35351"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35482"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34790"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35291"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35262"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35202"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-5.el5" test_ref="oval:org.mitre.oval:tst:35177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9492" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (crash) via crafted IPP packets.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0597"/>
        <description>Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (crash) via crafted IPP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:18.085-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:16.459-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:19.429-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9492 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:41.664-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:45.174-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.17-13.3.51" test_ref="oval:org.mitre.oval:tst:36392"/>
            <criterion comment="cups is earlier than 0:1.1.17-13.3.51" test_ref="oval:org.mitre.oval:tst:36393"/>
            <criterion comment="cups-libs is earlier than 0:1.1.17-13.3.51" test_ref="oval:org.mitre.oval:tst:36450"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" test_ref="oval:org.mitre.oval:tst:35932"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" test_ref="oval:org.mitre.oval:tst:36243"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" test_ref="oval:org.mitre.oval:tst:36438"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9491" version="5" class="vulnerability">
      <metadata>
        <title>EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2787" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2787"/>
        <description>EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:21.461-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:15.930-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:18.885-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9491 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:35.760-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:44.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9490" version="5" class="vulnerability">
      <metadata>
        <title>MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1626"/>
        <description>MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:30.870-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:15.539-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:18.642-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9490 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:48.428-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:44.183-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:40529"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:40467"/>
          <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:40387"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:40525"/>
          <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_5.3" test_ref="oval:org.mitre.oval:tst:39669"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9489" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0629" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0629"/>
        <description>Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:31.390-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:15.311-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:18.403-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9489 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:42.151-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:43.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:40333"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:40224"/>
          <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:40289"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:40134"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_5.2" test_ref="oval:org.mitre.oval:tst:39948"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9488" version="5" class="vulnerability">
      <metadata>
        <title>The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6120"/>
        <description>The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:36.652-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:14.892-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:17.959-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9488 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:17.716-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:43.279-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9487" version="5" class="vulnerability">
      <metadata>
        <title>The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1041"/>
        <description>The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:51.290-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:14.633-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:17.686-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9487 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:49.588-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:42.878-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
          <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9486" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1195"/>
        <description>Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:18.677-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:13.962-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:17.012-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36548"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36455"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36422"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36295"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36406"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36334"/>
            <criterion comment="java-1.5.0-ibm is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36155"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36267"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35708"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35618"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36613"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 0:1.5.0.7-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36614"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36509"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36558"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36485"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35872"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36582"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36555"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36414"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36622"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36688"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36265"/>
            <criterion comment="java-1.6.0-ibm is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36319"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36706"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36205"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36535"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 0:1.6.0.1-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36515"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36523"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36323"/>
            <criterion comment="java-1.5.0-ibm is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35890"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35698"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35719"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 0:1.5.0.7-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36340"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36068"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36568"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9485" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0691"/>
        <description>Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:08.746-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:13.732-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:16.768-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9485 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:37.994-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:42.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="qt-config is earlier than 1:3.1.2-13.4" test_ref="oval:org.mitre.oval:tst:30825"/>
          <criterion comment="qt is earlier than 1:3.1.2-13.4" test_ref="oval:org.mitre.oval:tst:30487"/>
          <criterion comment="qt-devel is earlier than 1:3.1.2-13.4" test_ref="oval:org.mitre.oval:tst:30732"/>
          <criterion comment="qt-MySQL is earlier than 1:3.1.2-13.4" test_ref="oval:org.mitre.oval:tst:30758"/>
          <criterion comment="qt-designer is earlier than 1:3.1.2-13.4" test_ref="oval:org.mitre.oval:tst:30345"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9484" version="5" class="vulnerability">
      <metadata>
        <title>WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1698" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1698"/>
        <description>WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:24.152-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:13.426-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:16.458-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9484 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:30.909-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:41.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs is earlier than 6:3.1.3-6.13" test_ref="oval:org.mitre.oval:tst:38767"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.1.3-6.13" test_ref="oval:org.mitre.oval:tst:38487"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs is earlier than 6:3.3.1-14.el4" test_ref="oval:org.mitre.oval:tst:37977"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-14.el4" test_ref="oval:org.mitre.oval:tst:38299"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:38102"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:38389"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:38720"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9483" version="5" class="vulnerability">
      <metadata>
        <title>BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1058"/>
        <description>BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:14.161-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:13.232-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:16.253-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9483 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:55.487-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:41.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="busybox-anaconda is earlier than 0:1.00.rc1-7.el4" test_ref="oval:org.mitre.oval:tst:33230"/>
          <criterion comment="busybox is earlier than 0:1.00.rc1-7.el4" test_ref="oval:org.mitre.oval:tst:33750"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9482" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via a crafted LDAP packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5740"/>
        <description>Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via a crafted LDAP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:09.293-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:12.944-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:15.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9482 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:57.587-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:41.187-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33205"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33170"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:32550"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:33152"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9481" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the libMagick componet of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2440"/>
        <description>Heap-based buffer overflow in the libMagick componet of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:19.462-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:12.626-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:15.598-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9481 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:22.562-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:40.696-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33189"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33318"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33102"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33080"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33315"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33269"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33326"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:32926"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:32622"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9480" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5378"/>
        <description>Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:23.200-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:12.285-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:15.244-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9480 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:15.516-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:40.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tix is earlier than 0:8.1.4-92.8" test_ref="oval:org.mitre.oval:tst:36200"/>
            <criterion comment="tclx is earlier than 0:8.3-92.8" test_ref="oval:org.mitre.oval:tst:35800"/>
            <criterion comment="tcl-devel is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:35961"/>
            <criterion comment="expect-devel is earlier than 0:5.38.0-92.8" test_ref="oval:org.mitre.oval:tst:36175"/>
            <criterion comment="tcltk is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36169"/>
            <criterion comment="itcl is earlier than 0:3.2-92.8" test_ref="oval:org.mitre.oval:tst:35879"/>
            <criterion comment="tcl is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36313"/>
            <criterion comment="expect is earlier than 0:5.38.0-92.8" test_ref="oval:org.mitre.oval:tst:35369"/>
            <criterion comment="tk-devel is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36316"/>
            <criterion comment="tk is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36018"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tk-devel is earlier than 0:8.4.7-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36356"/>
            <criterion comment="tk is earlier than 0:8.4.7-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36225"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9475" version="5" class="vulnerability">
      <metadata>
        <title>The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0052"/>
        <description>The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:02.110-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:12.068-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:14.943-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9475 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:12.831-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:39.835-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5.1-25.rhel3.5" test_ref="oval:org.mitre.oval:tst:32725"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5.1-34.rhel4.3" test_ref="oval:org.mitre.oval:tst:32480"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9474" version="5" class="vulnerability">
      <metadata>
        <title>The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0844"/>
        <description>The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:34.981-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:11.802-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:14.702-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9474 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:00.273-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:39.503-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="krb5-workstation is earlier than 0:1.6.1-31.el5_3.3" test_ref="oval:org.mitre.oval:tst:38425"/>
          <criterion comment="krb5 is earlier than 0:1.6.1-31.el5_3.3" test_ref="oval:org.mitre.oval:tst:38479"/>
          <criterion comment="krb5-libs is earlier than 0:1.6.1-31.el5_3.3" test_ref="oval:org.mitre.oval:tst:37893"/>
          <criterion comment="krb5-server is earlier than 0:1.6.1-31.el5_3.3" test_ref="oval:org.mitre.oval:tst:38211"/>
          <criterion comment="krb5-devel is earlier than 0:1.6.1-31.el5_3.3" test_ref="oval:org.mitre.oval:tst:38553"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9473" version="5" class="vulnerability">
      <metadata>
        <title>The HTTP dissector in Ethereal 0.10.1 through 0.10.7 allows remote attackers to cause a denial of service (application crash) via a certain packet that causes the dissector to access previously-freed memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1141"/>
        <description>The HTTP dissector in Ethereal 0.10.1 through 0.10.7 allows remote attackers to cause a denial of service (application crash) via a certain packet that causes the dissector to access previously-freed memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:12.964-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:11.563-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:14.451-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9473 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:38.712-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:39.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31265"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31097"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9472" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3055"/>
        <description>Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:14.540-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:11.156-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:13.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9472 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:54.579-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:38.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32158"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32589"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32704"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32562"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32078"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32513"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32231"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32097"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32708"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9471" version="5" class="vulnerability">
      <metadata>
        <title>Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a VTi domain to read memory of other domains.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6207"/>
        <description>Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a VTi domain to read memory of other domains.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:53.228-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:10.770-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:13.651-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9471 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:26.815-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:38.119-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36192"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36176"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36335"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36430"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35944"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36215"/>
          <criterion comment="kernel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36409"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35484"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35974"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35791"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36150"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9470" version="5" class="vulnerability">
      <metadata>
        <title>slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0658"/>
        <description>slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:15.462-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:10.434-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:13.297-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9470 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:57.943-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:37.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="compat-openldap is earlier than 0:2.1.30-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:36122"/>
            <criterion comment="openldap-devel is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:36157"/>
            <criterion comment="openldap-clients is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:35412"/>
            <criterion comment="openldap is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:36270"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:36239"/>
            <criterion comment="openldap-servers is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:35877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="compat-openldap is earlier than 0:2.3.27_2.2.29-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:35700"/>
            <criterion comment="openldap-devel is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:35900"/>
            <criterion comment="openldap-clients is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:36273"/>
            <criterion comment="openldap is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:36158"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:36065"/>
            <criterion comment="openldap-servers is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:35300"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:947" version="4" class="vulnerability">
      <metadata>
        <title>KAME IKE Daemon Improper Hash Value Handling</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0164" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0164"/>
        <description>KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:05.590-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.481-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.756-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:54:36.771-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:47.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ipsec-tools version is less than 0.2.5-0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1430"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="racoon is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9469" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0008"/>
        <description>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:32.733-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:10.246-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:13.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9469 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:33.435-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:37.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="gaim is earlier than 1:0.75-3.2.0" test_ref="oval:org.mitre.oval:tst:30440"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9468" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the NFS dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3632"/>
        <description>Buffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the NFS dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:10.759-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:09.965-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:12.799-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9468 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:10.632-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:36.893-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32882"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32738"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32917"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32447"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9467" version="5" class="vulnerability">
      <metadata>
        <title>The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory consumption).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3181"/>
        <description>The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:46.155-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:09.713-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:12.533-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9467 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:18.812-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:36.536-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32382"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32096"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32404"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32387"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32210"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32355"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9466" version="5" class="vulnerability">
      <metadata>
        <title>The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3525" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3525"/>
        <description>The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:19.393-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:09.509-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:12.317-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9466 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:51.376-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:36.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="xen-libs is earlier than 0:3.0.3-94.el5_4.1" test_ref="oval:org.mitre.oval:tst:39479"/>
          <criterion comment="xen is earlier than 0:3.0.3-94.el5_4.1" test_ref="oval:org.mitre.oval:tst:38860"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-94.el5_4.1" test_ref="oval:org.mitre.oval:tst:39042"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9463" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3380"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:19.986-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:08.911-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:11.727-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9463 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:27.084-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:35.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39570"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39466"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39720"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39691"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39583"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39727"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39575"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39481"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39675"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39683"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39031"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39547"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39753"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9462" version="5" class="vulnerability">
      <metadata>
        <title>The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0180"/>
        <description>The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:58.113-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:08.727-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:11.529-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9462 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:02.375-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:34.954-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="cvs is earlier than 0:1.11.2-18" test_ref="oval:org.mitre.oval:tst:30704"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9461" version="5" class="vulnerability">
      <metadata>
        <title>neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2473" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2473"/>
        <description>neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:43.398-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:08.488-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:11.278-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9461 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:31.582-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:34.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="neon is earlier than 0:0.24.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:38525"/>
            <criterion comment="neon-devel is earlier than 0:0.24.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:38882"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="neon is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:39020"/>
            <criterion comment="neon-devel is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:39410"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9460" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0839"/>
        <description>Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:47.573-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:08.228-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:10.948-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9460 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:28.098-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:34.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
          <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9459" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0357"/>
        <description>Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:42.242-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:07.602-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:10.290-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9459 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:20.171-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:33.401-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38173"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38181"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38221"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38323"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38337"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:37355"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38135"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38326"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38186"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38184"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38228"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37943"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37433"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38309"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38278"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9458" version="5" class="vulnerability">
      <metadata>
        <title>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:25.123-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:07.394-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:10.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9458 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:02.114-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:33.111-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="httpd-devel is earlier than 0:2.0.46-26.ent" test_ref="oval:org.mitre.oval:tst:30072"/>
          <criterion comment="mod_ssl is earlier than 1:2.0.46-26.ent" test_ref="oval:org.mitre.oval:tst:30465"/>
          <criterion comment="httpd is earlier than 0:2.0.46-26.ent" test_ref="oval:org.mitre.oval:tst:30309"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9456" version="5" class="vulnerability">
      <metadata>
        <title>A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3813"/>
        <description>A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:54.663-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:07.201-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:09.830-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9456 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:03.332-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:32.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="perl-suidperl is earlier than 3:5.8.5-36.RHEL4" test_ref="oval:org.mitre.oval:tst:32691"/>
          <criterion comment="perl is earlier than 3:5.8.5-36.RHEL4" test_ref="oval:org.mitre.oval:tst:32640"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9455" version="5" class="vulnerability">
      <metadata>
        <title>The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1303"/>
        <description>The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:50.725-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:06.661-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:09.324-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9455 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:42.824-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:32.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38597"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38375"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38403"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38521"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38542"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:37726"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38677"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38096"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38577"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38540"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38634"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38697"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38716"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38190"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38685"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38596"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9454" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3740"/>
        <description>Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:28.193-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:05.836-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:08.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9454 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:14.116-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:31.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32914"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32731"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32743"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:33049"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:33018"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32923"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:33030"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32967"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32863"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32067"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32995"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32642"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32901"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32927"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32766"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32821"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32286"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32798"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32943"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32071"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32966"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32931"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32847"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32849"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32945"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32827"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32897"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:33027"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32324"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32850"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32455"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32518"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32775"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32899"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32949"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32941"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:33005"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32769"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32227"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:33008"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32830"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32907"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:33034"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32741"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32935"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32792"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32908"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32709"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9453" version="5" class="vulnerability">
      <metadata>
        <title>The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1895"/>
        <description>The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:22.749-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:05.111-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:07.811-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9453 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:17.289-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:30.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39101"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39357"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38568"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39331"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39316"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39054"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39274"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39407"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39435"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39442"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38473"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38128"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38668"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38883"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38948"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38732"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38969"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38991"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:39056"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38817"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:39009"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38672"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9452" version="5" class="vulnerability">
      <metadata>
        <title>The Xen hypervisor block backend driver for Linux kernel 2.6.18, when running on a 64-bit host with a 32-bit paravirtualized guest, allows local privileged users in the guest OS to cause a denial of service (host OS crash) via a request that specifies a large number of blocks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5498" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5498"/>
        <description>The Xen hypervisor block backend driver for Linux kernel 2.6.18, when running on a 64-bit host with a 32-bit paravirtualized guest, allows local privileged users in the guest OS to cause a denial of service (host OS crash) via a request that specifies a large number of blocks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:40.940-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:04.746-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:07.470-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9452 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:16.374-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:29.790-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36107"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36600"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36529"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36526"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36442"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36238"/>
          <criterion comment="kernel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36463"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36480"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35876"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36532"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36278"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35724"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36560"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9450" version="5" class="vulnerability">
      <metadata>
        <title>The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1070"/>
        <description>The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:17.298-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:04.469-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:07.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9450 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:23.113-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:29.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30934"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30708"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30577"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30874"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30794"/>
          <criterion comment="kernel is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30892"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30873"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:31080"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-20.0.1.EL" test_ref="oval:org.mitre.oval:tst:30866"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:945" version="4" class="vulnerability">
      <metadata>
        <title>Racoon IKE Daemon Unauthorized X.509 Certificate Connection Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0155" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0155"/>
        <description>The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.509-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.312-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.756-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:54:36.869-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:46.730-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ipsec-tools version is less than 0.2.5-0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1430"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="racoon is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9449" version="5" class="vulnerability">
      <metadata>
        <title>The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5052"/>
        <description>The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:01.420-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:04.254-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:06.875-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9449 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:11.230-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:28.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9448" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1840"/>
        <description>Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:51.305-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:03.957-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:06.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9448 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:29.294-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:28.566-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9447" version="5" class="vulnerability">
      <metadata>
        <title>The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec + utrace_attach spin failure mode," as demonstrated by ptrace-thrash.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0771"/>
        <description>The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec + utrace_attach spin failure mode," as demonstrated by ptrace-thrash.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:51.975-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:03.656-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:06.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9447 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:11.148-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:28.152-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:33503"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:34071"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:33478"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:33985"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:34055"/>
          <criterion comment="kernel is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:34011"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:33805"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:33899"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:33709"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:34058"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.3.el5" test_ref="oval:org.mitre.oval:tst:34043"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9446" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0179"/>
        <description>Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:46.891-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:03.404-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:05.974-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9446 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:59.471-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:27.698-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.19-1.el4" test_ref="oval:org.mitre.oval:tst:40284"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40265"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:39621"/>
            <criterion comment="firefox is earlier than 0:3.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40064"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9445" version="5" class="vulnerability">
      <metadata>
        <title>pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2069"/>
        <description>pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:33.275-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:03.002-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:05.627-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9445 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:29.982-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:27.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openldap-devel is earlier than 0:2.0.27-20" test_ref="oval:org.mitre.oval:tst:32018"/>
            <criterion comment="openldap-clients is earlier than 0:2.0.27-20" test_ref="oval:org.mitre.oval:tst:31815"/>
            <criterion comment="nss_ldap is earlier than 0:207-17" test_ref="oval:org.mitre.oval:tst:32179"/>
            <criterion comment="openldap is earlier than 0:2.0.27-20" test_ref="oval:org.mitre.oval:tst:32086"/>
            <criterion comment="openldap-servers is earlier than 0:2.0.27-20" test_ref="oval:org.mitre.oval:tst:31961"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="compat-openldap is earlier than 0:2.1.30-4" test_ref="oval:org.mitre.oval:tst:32065"/>
            <criterion comment="openldap-devel is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:32089"/>
            <criterion comment="openldap-clients is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:31874"/>
            <criterion comment="nss_ldap is earlier than 0:226-10" test_ref="oval:org.mitre.oval:tst:31977"/>
            <criterion comment="openldap is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:31301"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:32188"/>
            <criterion comment="openldap-servers is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:32059"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9444" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3074"/>
        <description>Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:10.861-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:02.701-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:05.313-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9444 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:26.994-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:26.726-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39088"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el4" test_ref="oval:org.mitre.oval:tst:39195"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39208"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39001"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39223"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39097"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39150"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39206"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9443" version="5" class="vulnerability">
      <metadata>
        <title>The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2690" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2690"/>
        <description>The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:10.539-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:02.472-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:05.073-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9443 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:15.106-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:26.380-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38942"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38825"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38972"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38267"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:39037"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9442" version="5" class="vulnerability">
      <metadata>
        <title>snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than CVE-2005-2177.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4837"/>
        <description>snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than CVE-2005-2177.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:42.892-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:02.154-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:04.707-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9442 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:58.168-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:25.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31395"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:30763"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31684"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31547"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31390"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31408"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:30993"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31414"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31691"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9439" version="5" class="vulnerability">
      <metadata>
        <title>drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4537" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4537"/>
        <description>drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:58.267-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:01.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:04.223-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9439 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:20.428-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:25.254-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39702"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39797"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39763"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39709"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39503"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39617"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39773"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39516"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39093"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39662"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39657"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39645"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39650"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39813"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39095"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39770"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39099"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39700"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39408"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39590"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39719"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39789"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:38905"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9437" version="5" class="vulnerability">
      <metadata>
        <title>The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624"/>
        <description>The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:25.836-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:01.149-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:03.663-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9437 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:24.591-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:24.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32437"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32206"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:31553"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32284"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.4" test_ref="oval:org.mitre.oval:tst:32545"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32254"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32499"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9436" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0763"/>
        <description>Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:47.229-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:00.800-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:03.362-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9436 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:42.911-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:24.012-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30799"/>
          <criterion comment="mozilla is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30278"/>
          <criterion comment="mozilla-chat is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30755"/>
          <criterion comment="mozilla-mail is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30570"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30230"/>
          <criterion comment="mozilla-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30288"/>
          <criterion comment="mozilla-nss is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30323"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30339"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30813"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30660"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9435" version="5" class="vulnerability">
      <metadata>
        <title>init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0403" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0403"/>
        <description>init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:44.891-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:00.517-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:03.073-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9435 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:08.332-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:23.649-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
          <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9434" version="5" class="vulnerability">
      <metadata>
        <title>The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1920" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1920"/>
        <description>The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:34.816-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:00.324-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:02.832-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9434 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:03.168-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:23.350-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdelibs is earlier than 6:3.3.1-3.11" test_ref="oval:org.mitre.oval:tst:31875"/>
          <criterion comment="kdelibs-devel is earlier than 6:3.3.1-3.11" test_ref="oval:org.mitre.oval:tst:31922"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9433" version="5" class="vulnerability">
      <metadata>
        <title>The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0505" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0505"/>
        <description>The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:26.948-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:00.135-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:02.628-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9433 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:03.557-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:23.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ethereal-gnome is earlier than 0:0.10.3-0.30E.2" test_ref="oval:org.mitre.oval:tst:30484"/>
          <criterion comment="ethereal is earlier than 0:0.10.3-0.30E.2" test_ref="oval:org.mitre.oval:tst:30678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9432" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding instead of UTF-8 encoding in a French .properties file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2807"/>
        <description>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding instead of UTF-8 encoding in a French .properties file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:35.473-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:59.492-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:01.987-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9432 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:09.431-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:22.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9431" version="5" class="vulnerability">
      <metadata>
        <title>tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4315" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4315"/>
        <description>tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:52.891-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:59.294-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:01.778-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9431 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:46.163-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:21.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="tog-pegasus is earlier than 2:2.7.0-2.el5_2.1" test_ref="oval:org.mitre.oval:tst:38022"/>
          <criterion comment="tog-pegasus-devel is earlier than 2:2.7.0-2.el5_2.1" test_ref="oval:org.mitre.oval:tst:38089"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:943" version="2" class="vulnerability">
      <metadata>
        <title>Solaris Xsun and Xprt Unspecified Local Privilege Escalation</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Xsun</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3099"/>
        <description>Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:54.666-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:01.243-04:00">ACCEPTED</status_change>
            <modified comment="Corrected CVE reference and title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:00:00.106-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:01:36.132-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:28.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criterion comment="Solaris 7 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 108652-93 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3400"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 108653-82 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3355"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112785-50 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4130"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 112786-39 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3404"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 119059-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3997"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 119060-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3529"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criteria operator="AND" comment="File Xsun is SUID|SGID AND Executable" negate="false">
            <criteria operator="OR" comment="File Xsun SUID|SGID" negate="false">
              <criterion comment="File Xsun SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3963"/>
              <criterion comment="File Xprt SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3558"/>
            </criteria>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3178"/>
          </criteria>
          <criteria operator="AND" comment="File Xprt is SUID|SGID AND Executable" negate="false">
            <criteria operator="OR" comment="File Xprt SUID|SGID" negate="false">
              <criterion comment="File Xsun SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3963"/>
              <criterion comment="File Xprt SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3558"/>
            </criteria>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9429" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0500"/>
        <description>Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:53.449-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:59.117-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:01.580-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9429 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:02.588-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:21.639-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="gaim is earlier than 1:0.82.1-0.RHEL3" test_ref="oval:org.mitre.oval:tst:30434"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9427" version="5" class="vulnerability">
      <metadata>
        <title>The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0178" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0178"/>
        <description>The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:05.363-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:58.787-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:01.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9427 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:20.216-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:21.277-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30827"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30622"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30627"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30676"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30823"/>
          <criterion comment="kernel is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30750"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30596"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30833"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30830"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9426" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0554"/>
        <description>Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:34.123-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:58.500-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:00.953-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9426 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:36.883-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:20.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-15.0.2.EL" test_ref="oval:org.mitre.oval:tst:30449"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-15.0.2.EL" test_ref="oval:org.mitre.oval:tst:30739"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.2.EL" test_ref="oval:org.mitre.oval:tst:30418"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.2.EL" test_ref="oval:org.mitre.oval:tst:30721"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-15.0.2.EL" test_ref="oval:org.mitre.oval:tst:30772"/>
          <criterion comment="kernel is earlier than 0:2.4.21-15.0.2.EL" test_ref="oval:org.mitre.oval:tst:30655"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-15.0.2.EL" test_ref="oval:org.mitre.oval:tst:30574"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-15.0.2.EL" test_ref="oval:org.mitre.oval:tst:30681"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-15.0.2.EL" test_ref="oval:org.mitre.oval:tst:30207"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9424" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2872" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2872"/>
        <description>Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:35.882-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:57.755-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:00.128-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9424 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:45.125-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:19.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35216"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35012"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34787"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35164"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34818"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35171"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34820"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35008"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34796"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35363"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35010"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35249"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34683"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34365"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34976"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35087"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35298"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35289"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35309"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35263"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35279"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34964"/>
            <criterion comment="php-common is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34896"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35084"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35078"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34802"/>
            <criterion comment="php is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35270"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35361"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34769"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35108"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35037"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34943"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34689"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35221"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35077"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34934"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35170"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34376"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34764"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9423" version="5" class="vulnerability">
      <metadata>
        <title>kmod in the Linux kernel does not set its uid, suid, gid, or sgid to 0, which allows local users to cause a denial of service (crash) by sending certain signals to kmod.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1040" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1040"/>
        <description>kmod in the Linux kernel does not set its uid, suid, gid, or sgid to 0, which allows local users to cause a denial of service (crash) by sending certain signals to kmod.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:30.259-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:57.474-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:59.788-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9423 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:25.887-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:19.190-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30346"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30006"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30702"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30513"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30280"/>
          <criterion comment="kernel is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30056"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30508"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30654"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9421" version="5" class="vulnerability">
      <metadata>
        <title>slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0277" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0277"/>
        <description>slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:21.380-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:57.001-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:59.350-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9421 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:43.684-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:18.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39911"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40093"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40218"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40181"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40052"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39983"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39933"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40004"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40214"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39974"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40080"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40176"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40248"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40202"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40141"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39917"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40306"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39993"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9420" version="5" class="vulnerability">
      <metadata>
        <title>libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6351"/>
        <description>libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:42.219-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:56.806-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:59.138-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9420 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:24.154-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:17.963-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="libexif-devel is earlier than 0:0.6.13-4.0.2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35024"/>
          <criterion comment="libexif is earlier than 0:0.6.13-4.0.2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35823"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9419" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0764"/>
        <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:14.920-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:56.519-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:58.782-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9419 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:24.571-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:17.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30799"/>
          <criterion comment="mozilla is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30278"/>
          <criterion comment="mozilla-chat is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30755"/>
          <criterion comment="mozilla-mail is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30570"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30230"/>
          <criterion comment="mozilla-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30288"/>
          <criterion comment="mozilla-nss is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30323"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30339"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30813"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30660"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9417" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0421"/>
        <description>Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:09.987-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:56.197-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:58.449-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9417 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:21.761-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:17.012-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pango-devel is earlier than 0:1.2.5-10" test_ref="oval:org.mitre.oval:tst:40152"/>
            <criterion comment="pango is earlier than 0:1.2.5-10" test_ref="oval:org.mitre.oval:tst:39329"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pango-devel is earlier than 0:1.6.0-16.el4_8" test_ref="oval:org.mitre.oval:tst:39573"/>
            <criterion comment="evolution28-pango-devel is earlier than 0:1.14.9-13.el4_8" test_ref="oval:org.mitre.oval:tst:40323"/>
            <criterion comment="pango is earlier than 0:1.6.0-16.el4_8" test_ref="oval:org.mitre.oval:tst:39891"/>
            <criterion comment="evolution28-pango is earlier than 0:1.14.9-13.el4_8" test_ref="oval:org.mitre.oval:tst:39360"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pango-devel is earlier than 0:1.14.9-8.el5" test_ref="oval:org.mitre.oval:tst:40132"/>
            <criterion comment="pango is earlier than 0:1.14.9-8.el5" test_ref="oval:org.mitre.oval:tst:40189"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9415" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0962" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0962"/>
        <description>Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:03.486-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:55.965-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:58.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9415 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:57.194-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:16.743-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="rsync is earlier than 0:2.5.7-1" test_ref="oval:org.mitre.oval:tst:30221"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9414" version="5" class="vulnerability">
      <metadata>
        <title>The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3615"/>
        <description>The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:49.763-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:55.517-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:57.734-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9414 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:08.899-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:16.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="pidgin is earlier than 0:1.5.1-6.el3" test_ref="oval:org.mitre.oval:tst:39353"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39708"/>
            <criterion comment="libpurple is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39368"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39729"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39606"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39458"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39406"/>
            <criterion comment="finch is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39382"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39309"/>
            <criterion comment="pidgin is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39454"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39342"/>
            <criterion comment="libpurple is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39335"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39751"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39174"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39298"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39584"/>
            <criterion comment="finch is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39392"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39508"/>
            <criterion comment="pidgin is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39728"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9413" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the ole_info_read_metabat function in Gnome Structured File library (libgsf) 1.14.0, and other versions before 1.14.2, allows context-dependent attackers to execute arbitrary code via a large num_metabat value in an OLE document, which causes the ole_init_info function to allocate insufficient memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4514" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4514"/>
        <description>Heap-based buffer overflow in the ole_info_read_metabat function in Gnome Structured File library (libgsf) 1.14.0, and other versions before 1.14.2, allows context-dependent attackers to execute arbitrary code via a large num_metabat value in an OLE document, which causes the ole_init_info function to allocate insufficient memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:29.075-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:55.275-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:57.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9413 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:56.540-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:15.688-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libgsf is earlier than 0:1.6.0-7" test_ref="oval:org.mitre.oval:tst:33304"/>
            <criterion comment="libgsf-devel is earlier than 0:1.6.0-7" test_ref="oval:org.mitre.oval:tst:32479"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libgsf is earlier than 0:1.10.1-2" test_ref="oval:org.mitre.oval:tst:33333"/>
            <criterion comment="libgsf-devel is earlier than 0:1.10.1-2" test_ref="oval:org.mitre.oval:tst:33257"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9412" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0007"/>
        <description>Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:59.884-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:54.451-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:56.800-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9412 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:23.076-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:14.843-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35915"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35794"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36513"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36264"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36161"/>
            <criterion comment="kernel is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36518"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36597"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36612"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36201"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36534"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36373"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36702"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36615"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36490"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36370"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35738"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36249"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36731"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35733"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36107"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36600"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36529"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36526"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36442"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36238"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36463"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36480"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35876"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36532"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36278"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35724"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36560"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9411" version="5" class="vulnerability">
      <metadata>
        <title>sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2104"/>
        <description>sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:49.875-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:54.230-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:56.560-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9411 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:55.250-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:14.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="sysreport is earlier than 0:1.3.7.2-9" test_ref="oval:org.mitre.oval:tst:31930"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="sysreport is earlier than 0:1.3.15-5" test_ref="oval:org.mitre.oval:tst:31910"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:941" version="4" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Squid ACL Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0189"/>
        <description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.635-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.144-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.366-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T21:00:44.025-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:46.445-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="squid version is less than 2.5.STABLE3-5.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1431"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9409" version="5" class="vulnerability">
      <metadata>
        <title>The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3228"/>
        <description>The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:28.297-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:53.704-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:56.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9409 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:19.184-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:13.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39477"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:38676"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39556"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39526"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:38895"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39250"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39485"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39492"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39608"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39456"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39277"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39665"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39142"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39538"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39699"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39518"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39350"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39738"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39663"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39536"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39189"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39141"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39179"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9408" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0100"/>
        <description>Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:47.264-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:53.313-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:55.622-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9408 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:02:57.349-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:13.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xemacs-el is earlier than 0:21.4.13-8.ent.1" test_ref="oval:org.mitre.oval:tst:31334"/>
            <criterion comment="xemacs is earlier than 0:21.4.13-8.ent.1" test_ref="oval:org.mitre.oval:tst:31358"/>
            <criterion comment="xemacs-info is earlier than 0:21.4.13-8.ent.1" test_ref="oval:org.mitre.oval:tst:31061"/>
            <criterion comment="emacs-el is earlier than 0:21.3-4.1" test_ref="oval:org.mitre.oval:tst:31186"/>
            <criterion comment="emacs-leim is earlier than 0:21.3-4.1" test_ref="oval:org.mitre.oval:tst:30740"/>
            <criterion comment="emacs is earlier than 0:21.3-4.1" test_ref="oval:org.mitre.oval:tst:31379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xemacs-nox is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:30840"/>
            <criterion comment="emacs-nox is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:31124"/>
            <criterion comment="xemacs-el is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:31326"/>
            <criterion comment="emacs-el is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:30860"/>
            <criterion comment="emacs-leim is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:31288"/>
            <criterion comment="emacs is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:31389"/>
            <criterion comment="emacs-common is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:31328"/>
            <criterion comment="xemacs is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:31171"/>
            <criterion comment="xemacs-info is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:30965"/>
            <criterion comment="xemacs-common is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:31034"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9407" version="5" class="vulnerability">
      <metadata>
        <title>Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1721"/>
        <description>Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:13.536-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:52.964-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:55.295-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9407 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:02.286-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:12.524-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38916"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38703"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38787"/>
            <criterion comment="python is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38939"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38889"/>
            <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38958"/>
            <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38827"/>
            <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9406" version="5" class="vulnerability">
      <metadata>
        <title>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0984"/>
        <description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:10.680-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:52.687-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:54.943-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9406 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:37.614-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:12.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30346"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30006"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30702"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30513"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30280"/>
          <criterion comment="kernel is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30056"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30508"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30654"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9405" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1738"/>
        <description>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:42.534-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:52.201-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:54.433-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9405 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:09.273-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:11.464-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9403" version="5" class="vulnerability">
      <metadata>
        <title>The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1890"/>
        <description>The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:17.503-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:51.928-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:54.192-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9403 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:44:04.090-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:11.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38846"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38761"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38385"/>
          <criterion comment="httpd is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38816"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9402" version="5" class="vulnerability">
      <metadata>
        <title>The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0069"/>
        <description>The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:06.609-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:51.611-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:53.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9402 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:10.954-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:10.653-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:31098"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:30910"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:31254"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:30835"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:30437"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31180"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31161"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31316"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31312"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31163"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:940" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel ISO9660 File System Component BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109"/>
        <description>Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:31.517-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="kernel versions">
            <criterion comment="kernel version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1436"/>
            <criterion comment="kernel-smp version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1435"/>
            <criterion comment="kernel-hugemem version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1434"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/bin/mount is world-executable AND Set-UID">
            <criterion comment="/bin/mount is world-executable AND Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:1433"/>
            <criterion comment="/bin/mount is world-executable AND Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:1432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:94" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 mibiisa Remote Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mibiisa</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0797"/>
        <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File mibiisa exists" negate="false" test_ref="oval:org.mitre.oval:tst:2995"/>
          <criterion comment="Patch 108869-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3125"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mibiisa running" negate="false" test_ref="oval:org.mitre.oval:tst:2993"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9399" version="5" class="vulnerability">
      <metadata>
        <title>The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0415"/>
        <description>The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:14.880-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:51.292-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:53.496-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9399 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:00.679-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:10.227-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40228"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40098"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40231"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39918"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39938"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40088"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40237"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39997"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40240"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40352"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39930"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40055"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9398" version="5" class="vulnerability">
      <metadata>
        <title>Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0587"/>
        <description>Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:22.284-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:50.968-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:53.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9398 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:13.190-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:09.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30827"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30622"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30627"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30676"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30823"/>
          <criterion comment="kernel is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30750"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30596"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30833"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-15.0.4.EL" test_ref="oval:org.mitre.oval:tst:30830"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9397" version="5" class="vulnerability">
      <metadata>
        <title>The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2721"/>
        <description>The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:00.671-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:50.704-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:52.883-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9397 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:10.317-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:09.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="netpbm is earlier than 0:10.25-2.1.el4_7.4" test_ref="oval:org.mitre.oval:tst:37861"/>
            <criterion comment="netpbm-progs is earlier than 0:10.25-2.1.el4_7.4" test_ref="oval:org.mitre.oval:tst:38005"/>
            <criterion comment="netpbm-devel is earlier than 0:10.25-2.1.el4_7.4" test_ref="oval:org.mitre.oval:tst:38171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="netpbm is earlier than 0:10.35-6.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:37534"/>
            <criterion comment="netpbm-progs is earlier than 0:10.35-6.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:37722"/>
            <criterion comment="netpbm-devel is earlier than 0:10.35-6.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:37227"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9396" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in the ip6_input_finish function in ip6_input.c in Linux kernel 2.6.12 and earlier might allow attackers to cause a denial of service via malformed IPv6 packets with unspecified parameter problems, which prevents the SKB from being freed.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3858" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3858"/>
        <description>Memory leak in the ip6_input_finish function in ip6_input.c in Linux kernel 2.6.12 and earlier might allow attackers to cause a denial of service via malformed IPv6 packets with unspecified parameter problems, which prevents the SKB from being freed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:57.736-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:50.315-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:52.483-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9396 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:13.301-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:08.817-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9393" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in libUil (libUil.so) in OpenMotif 2.2.3, and possibly other versions, allows attackers to execute arbitrary code via the (1) diag_issue_diagnostic function in UilDiags.c and (2) open_source_file function in UilSrcSrc.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3964" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3964"/>
        <description>Multiple buffer overflows in libUil (libUil.so) in OpenMotif 2.2.3, and possibly other versions, allows attackers to execute arbitrary code via the (1) diag_issue_diagnostic function in UilDiags.c and (2) open_source_file function in UilSrcSrc.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:32.388-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:49.961-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:52.189-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9393 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:25.066-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:08.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.7" test_ref="oval:org.mitre.oval:tst:32680"/>
            <criterion comment="openmotif-devel is earlier than 0:2.2.3-5.RHEL3.3" test_ref="oval:org.mitre.oval:tst:32681"/>
            <criterion comment="openmotif is earlier than 0:2.2.3-5.RHEL3.3" test_ref="oval:org.mitre.oval:tst:32716"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openmotif21 is earlier than 0:2.1.30-11.RHEL4.5" test_ref="oval:org.mitre.oval:tst:32013"/>
            <criterion comment="openmotif-devel is earlier than 0:2.2.3-10.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32468"/>
            <criterion comment="openmotif is earlier than 0:2.2.3-10.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32612"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9392" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1308"/>
        <description>Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:41.137-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:49.719-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:51.886-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9392 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:43.369-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:07.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-22.el3" test_ref="oval:org.mitre.oval:tst:31219"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-22.el3" test_ref="oval:org.mitre.oval:tst:30876"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-8" test_ref="oval:org.mitre.oval:tst:31174"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-8" test_ref="oval:org.mitre.oval:tst:30884"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9390" version="5" class="vulnerability">
      <metadata>
        <title>The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1862"/>
        <description>The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:37.254-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:49.442-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:51.598-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9390 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:11.351-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:07.566-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:939" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel ip_setsockopt Integer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0424" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0424"/>
        <description>Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:59.136-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="kernel versions">
          <criterion comment="kernel version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1436"/>
          <criterion comment="kernel-smp version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1435"/>
          <criterion comment="kernel-hugemem version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1434"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9388" version="5" class="vulnerability">
      <metadata>
        <title>kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2494"/>
        <description>kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:14.333-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:49.243-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:51.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9388 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:00.302-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:07.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdebase is earlier than 6:3.3.1-5.13" test_ref="oval:org.mitre.oval:tst:32841"/>
          <criterion comment="kdebase-devel is earlier than 6:3.3.1-5.13" test_ref="oval:org.mitre.oval:tst:32807"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9386" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2800"/>
        <description>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:21.390-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:48.607-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:50.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9386 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:27.340-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:06.367-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9385" version="5" class="vulnerability">
      <metadata>
        <title>The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocations of the Netperf benchmark application in UDP_STREAM mode.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5713" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5713"/>
        <description>The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocations of the Netperf benchmark application in UDP_STREAM mode.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:11.185-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:48.289-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:50.336-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9385 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:36.920-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:05.903-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37732"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38060"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38354"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38313"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38198"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37887"/>
          <criterion comment="kernel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38174"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38191"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38124"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38417"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37779"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38257"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9384" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3988"/>
        <description>Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:09.517-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:47.977-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:49.866-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9384 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:23.149-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:04.935-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9383" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of "useless newly zeroed pages."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2372"/>
        <description>The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of "useless newly zeroed pages."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:20.300-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:47.666-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:49.535-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9383 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:01.410-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:04.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37778"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37855"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37870"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37881"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37504"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37738"/>
          <criterion comment="kernel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37774"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37247"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37715"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37954"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37668"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37947"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9382" version="5" class="vulnerability">
      <metadata>
        <title>The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1163" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1163"/>
        <description>The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:41.877-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:47.483-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:49.337-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9382 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:28.973-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:04.076-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criterion comment="sudo is earlier than 0:1.7.2p1-6.el5_5" test_ref="oval:org.mitre.oval:tst:40014"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9379" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3999" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3999"/>
        <description>Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:01.163-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:47.184-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:48.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9379 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:29.519-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:03.572-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nfs-utils-lib-devel is earlier than 0:1.0.6-8.z1" test_ref="oval:org.mitre.oval:tst:34626"/>
            <criterion comment="nfs-utils-lib is earlier than 0:1.0.6-8.z1" test_ref="oval:org.mitre.oval:tst:35367"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nfs-utils-lib-devel is earlier than 0:1.0.8-7.2.z2" test_ref="oval:org.mitre.oval:tst:35168"/>
            <criterion comment="nfs-utils-lib is earlier than 0:1.0.8-7.2.z2" test_ref="oval:org.mitre.oval:tst:35408"/>
            <criterion comment="krb5-workstation is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:34835"/>
            <criterion comment="krb5 is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:35134"/>
            <criterion comment="krb5-libs is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:34559"/>
            <criterion comment="krb5-server is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:35091"/>
            <criterion comment="krb5-devel is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:34927"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9378" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0722"/>
        <description>Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:31.789-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:46.824-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:48.666-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9378 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:21.104-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:03.190-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30799"/>
          <criterion comment="mozilla is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30278"/>
          <criterion comment="mozilla-chat is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30755"/>
          <criterion comment="mozilla-mail is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30570"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30230"/>
          <criterion comment="mozilla-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30288"/>
          <criterion comment="mozilla-nss is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30323"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30339"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30813"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30660"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9376" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5507"/>
        <description>Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:41.611-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:46.143-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:47.971-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9376 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:44.607-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:02.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38137"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37999"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37907"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37709"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38092"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37745"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38039"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38062"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38073"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38071"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:37200"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37812"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37869"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37789"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37395"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:38053"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:37631"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38114"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37737"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9375" version="5" class="vulnerability">
      <metadata>
        <title>The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0182"/>
        <description>The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:13.424-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:45.707-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:47.563-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9375 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:15.596-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:01.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.6.4-8.el4" test_ref="oval:org.mitre.oval:tst:40755"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnome-python2-extras is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40435"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40552"/>
            <criterion comment="gnome-python2-libegg is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40721"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40480"/>
            <criterion comment="gnome-python2-gtkhtml2 is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40813"/>
            <criterion comment="totem is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40749"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40221"/>
            <criterion comment="gnome-python2-gtkspell is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40385"/>
            <criterion comment="yelp is earlier than 0:2.16.0-26.el5" test_ref="oval:org.mitre.oval:tst:40828"/>
            <criterion comment="devhelp is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40814"/>
            <criterion comment="firefox is earlier than 0:3.6.4-8.el5" test_ref="oval:org.mitre.oval:tst:40524"/>
            <criterion comment="totem-mozplugin is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40620"/>
            <criterion comment="gnome-python2-gtkmozembed is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40722"/>
            <criterion comment="esc is earlier than 0:1.1.0-12.el5" test_ref="oval:org.mitre.oval:tst:40273"/>
            <criterion comment="totem-devel is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9373" version="5" class="vulnerability">
      <metadata>
        <title>The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1168"/>
        <description>The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:42.556-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:45.490-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:47.326-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9373 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:36.486-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:01.332-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="ncompress is earlier than 0:4.2.4-39.rhel3" test_ref="oval:org.mitre.oval:tst:32891"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="ncompress is earlier than 0:4.2.4-43.rhel4" test_ref="oval:org.mitre.oval:tst:32529"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9371" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5753"/>
        <description>Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:01.617-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:45.214-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:46.653-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9371 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:31.838-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:00.887-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9370" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738"/>
        <description>Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:56.422-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:44.766-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:46.354-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9370 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:53.800-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:00.454-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.21" test_ref="oval:org.mitre.oval:tst:32990"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.21" test_ref="oval:org.mitre.oval:tst:32592"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.21" test_ref="oval:org.mitre.oval:tst:32812"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.46" test_ref="oval:org.mitre.oval:tst:32771"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.14" test_ref="oval:org.mitre.oval:tst:32875"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.14" test_ref="oval:org.mitre.oval:tst:33058"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.14" test_ref="oval:org.mitre.oval:tst:33093"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-22.46" test_ref="oval:org.mitre.oval:tst:32789"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:937" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Mozilla Zombie Document Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0191"/>
        <description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.073-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.540-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false" test_ref="oval:org.mitre.oval:tst:1468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9369" version="5" class="vulnerability">
      <metadata>
        <title>SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1190"/>
        <description>SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:52.203-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:44.505-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:46.089-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9369 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:44.183-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:00.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9367" version="5" class="vulnerability">
      <metadata>
        <title>The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4770"/>
        <description>The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:58.120-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:44.212-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:45.699-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9367 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:40.958-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:59.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vnc-server is earlier than 0:4.0-0.beta4.1.8" test_ref="oval:org.mitre.oval:tst:38057"/>
            <criterion comment="vnc is earlier than 0:4.0-0.beta4.1.8" test_ref="oval:org.mitre.oval:tst:38376"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vnc-server is earlier than 0:4.0-12.el4_7.1" test_ref="oval:org.mitre.oval:tst:38179"/>
            <criterion comment="vnc is earlier than 0:4.0-12.el4_7.1" test_ref="oval:org.mitre.oval:tst:38424"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vnc-server is earlier than 0:4.1.2-14.el5_3.1" test_ref="oval:org.mitre.oval:tst:38345"/>
            <criterion comment="vnc is earlier than 0:4.1.2-14.el5_3.1" test_ref="oval:org.mitre.oval:tst:38082"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9364" version="5" class="vulnerability">
      <metadata>
        <title>The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability before processing a (1) SIOCDEVRESINSTATS, (2) SIOCDEVSHWSTATE, (3) SIOCDEVENSLAVE, or (4) SIOCDEVEMANSIPATE ioctl request, which allows local users to bypass intended capability restrictions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3525" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3525"/>
        <description>The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability before processing a (1) SIOCDEVRESINSTATS, (2) SIOCDEVSHWSTATE, (3) SIOCDEVENSLAVE, or (4) SIOCDEVEMANSIPATE ioctl request, which allows local users to bypass intended capability restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:01.405-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:43.904-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:45.404-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9364 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:58.584-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:58.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37931"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37846"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37817"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37663"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37799"/>
          <criterion comment="kernel is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37028"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37885"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37981"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37117"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9363" version="5" class="vulnerability">
      <metadata>
        <title>The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095"/>
        <description>The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:30.129-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:43.544-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:44.985-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9363 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:51.358-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:58.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:39637"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:39671"/>
            <criterion comment="httpd is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:39611"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39448"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39501"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:38802"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39716"/>
            <criterion comment="httpd is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39551"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39267"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39640"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39613"/>
            <criterion comment="httpd is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39756"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9360" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3871"/>
        <description>Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:06.392-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:43.315-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:44.743-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9360 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:19.730-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:57.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:38878"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39616"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39115"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39531"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39655"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9359" version="5" class="vulnerability">
      <metadata>
        <title>The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2672"/>
        <description>The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:51.502-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:43.087-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:44.502-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9359 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:17.992-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:57.368-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38942"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38825"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38972"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38267"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:39037"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9358" version="5" class="vulnerability">
      <metadata>
        <title>PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4136"/>
        <description>PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:37.084-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:42.412-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:43.815-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9358 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:55.956-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:56.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40180"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40440"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40426"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40220"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:39618"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40140"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40502"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:39925"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40137"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40551"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40486"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40521"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40292"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40516"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40066"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40399"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40512"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40314"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40428"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40366"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40465"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40401"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40402"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40538"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:39839"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40515"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40505"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40251"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40253"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40509"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40309"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9357" version="5" class="vulnerability">
      <metadata>
        <title>ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097"/>
        <description>ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:31.561-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:42.138-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:43.535-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9357 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:53.264-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:56.119-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="bind-utils is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:40044"/>
          <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39542"/>
          <criterion comment="bind-devel is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39904"/>
          <criterion comment="bind-chroot is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39693"/>
          <criterion comment="caching-nameserver is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39892"/>
          <criterion comment="bind-sdb is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:40054"/>
          <criterion comment="bind is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39489"/>
          <criterion comment="bind-libs is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39885"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9356" version="5" class="vulnerability">
      <metadata>
        <title>XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625"/>
        <description>XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:03.440-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:41.778-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:43.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9356 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:09.980-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:55.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="xerces-j2-demo is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:39659"/>
          <criterion comment="xerces-j2 is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:38778"/>
          <criterion comment="xerces-j2-scripts is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:39482"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38267"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:39037"/>
          <criterion comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:39592"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38825"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38942"/>
          <criterion comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:39411"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.2.b09.el5" test_ref="oval:org.mitre.oval:tst:38972"/>
          <criterion comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:39706"/>
          <criterion comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-7jpp.2.el5_4.2" test_ref="oval:org.mitre.oval:tst:39495"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9353" version="5" class="vulnerability">
      <metadata>
        <title>dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0595" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0595"/>
        <description>dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:04.388-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:41.573-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:42.934-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9353 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:29.747-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:55.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="dbus-devel is earlier than 0:1.0.0-6.3.el5_1" test_ref="oval:org.mitre.oval:tst:35564"/>
          <criterion comment="dbus-x11 is earlier than 0:1.0.0-6.3.el5_1" test_ref="oval:org.mitre.oval:tst:36228"/>
          <criterion comment="dbus is earlier than 0:1.0.0-6.3.el5_1" test_ref="oval:org.mitre.oval:tst:36008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:935" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.649-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.897-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:935 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:25.156-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:49.198-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:1442"/>
        <criterion negate="true" comment="Patch PHNE_32606 is installed" test_ref="oval:org.mitre.oval:tst:1441"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9349" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4168"/>
        <description>Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:32.480-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:41.334-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:42.676-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9349 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:43.399-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:54.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libexif-devel is earlier than 0:0.5.12-5.1.0.2" test_ref="oval:org.mitre.oval:tst:34690"/>
            <criterion comment="libexif is earlier than 0:0.5.12-5.1.0.2" test_ref="oval:org.mitre.oval:tst:34611"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libexif-devel is earlier than 0:0.6.13-4.0.2.el5" test_ref="oval:org.mitre.oval:tst:34381"/>
            <criterion comment="libexif is earlier than 0:0.6.13-4.0.2.el5" test_ref="oval:org.mitre.oval:tst:34026"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9348" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0783"/>
        <description>Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:24.303-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:41.093-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:42.435-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9348 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:57.097-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:54.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-11.3.3" test_ref="oval:org.mitre.oval:tst:30887"/>
          <criterion comment="gtk2 is earlier than 0:2.2.4-8.1" test_ref="oval:org.mitre.oval:tst:30146"/>
          <criterion comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-11.3.3" test_ref="oval:org.mitre.oval:tst:30822"/>
          <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-11.3.3" test_ref="oval:org.mitre.oval:tst:30571"/>
          <criterion comment="gtk2-devel is earlier than 0:2.2.4-8.1" test_ref="oval:org.mitre.oval:tst:30817"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9345" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0247" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0247"/>
        <description>Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:08.972-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:40.585-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:41.928-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9345 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:50.234-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:53.747-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:30936"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:30803"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31436"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31064"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:30591"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31342"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31217"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31199"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31415"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31005"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31233"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31336"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31398"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31229"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:30946"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31215"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:30784"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31126"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31318"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31273"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31424"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31325"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9343" version="5" class="vulnerability">
      <metadata>
        <title>The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1410"/>
        <description>The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:51.394-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:40.121-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:41.453-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9343 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:45.620-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:53.144-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31824"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31255"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31711"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31608"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31726"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31681"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31497"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31715"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31510"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31754"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31507"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31832"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31880"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31527"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31669"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31129"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31756"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31799"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31798"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31618"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31468"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31708"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9337" version="5" class="vulnerability">
      <metadata>
        <title>The Distributed Lock Manager (DLM) in the cluster manager for Linux kernel 2.6.15 allows remote attackers to cause a denial of service (loss of lock services) by connecting to the DLM port, which probably prevents other processes from accessing the service.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3380"/>
        <description>The Distributed Lock Manager (DLM) in the cluster manager for Linux kernel 2.6.15 allows remote attackers to cause a denial of service (loss of lock services) by connecting to the DLM port, which probably prevents other processes from accessing the service.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:00.376-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:39.754-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:41.137-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9337 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:38.619-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:52.688-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35330"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35339"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35337"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35227"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35043"/>
          <criterion comment="kernel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35276"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:34448"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35366"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35208"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35326"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35345"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9336" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4476"/>
        <description>Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:10.748-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:39.517-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:40.843-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9336 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:41.541-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:52.299-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="tar is earlier than 0:1.14-13.el4_8.1" test_ref="oval:org.mitre.oval:tst:40247"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tar is earlier than 2:1.15.1-23.0.1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39957"/>
            <criterion comment="cpio is earlier than 0:2.6-23.el5_4.1" test_ref="oval:org.mitre.oval:tst:40260"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9334" version="5" class="vulnerability">
      <metadata>
        <title>KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0689"/>
        <description>KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:03.458-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:38.869-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:40.614-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9334 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:26.641-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:51.932-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdebase is earlier than 6:3.1.3-5.4" test_ref="oval:org.mitre.oval:tst:30731"/>
          <criterion comment="kdebase-devel is earlier than 6:3.1.3-5.4" test_ref="oval:org.mitre.oval:tst:29837"/>
          <criterion comment="kdelibs is earlier than 6:3.1.3-6.6" test_ref="oval:org.mitre.oval:tst:30063"/>
          <criterion comment="kdelibs-devel is earlier than 6:3.1.3-6.6" test_ref="oval:org.mitre.oval:tst:30768"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9332" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2022"/>
        <description>Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:26.745-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:38.571-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:40.317-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9332 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:30.615-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:51.455-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.1.3-5.16" test_ref="oval:org.mitre.oval:tst:34248"/>
            <criterion comment="kdebase-devel is earlier than 6:3.1.3-5.16" test_ref="oval:org.mitre.oval:tst:34656"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.3.1-5.19.rhel4" test_ref="oval:org.mitre.oval:tst:34288"/>
            <criterion comment="kdebase-devel is earlier than 6:3.3.1-5.19.rhel4" test_ref="oval:org.mitre.oval:tst:34025"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.5.4-13.6.el5" test_ref="oval:org.mitre.oval:tst:34519"/>
            <criterion comment="kdebase-devel is earlier than 6:3.5.4-13.6.el5" test_ref="oval:org.mitre.oval:tst:34351"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9331" version="3" class="vulnerability">
      <metadata>
        <title>Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5232"/>
        <description>Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:49.716-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:37.464-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:39.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criteria operator="OR">
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:35438"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:36312"/>
            <criterion comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.1.el3" test_ref="oval:org.mitre.oval:tst:36020"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:36170"/>
            <criterion comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.1.el3" test_ref="oval:org.mitre.oval:tst:36131"/>
            <criterion comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.1.el3" test_ref="oval:org.mitre.oval:tst:35578"/>
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:35718"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:36338"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:35439"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35617"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:34688"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35272"/>
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35892"/>
            <criterion comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35850"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:34849"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36357"/>
            <criterion comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36067"/>
            <criterion comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35854"/>
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35532"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35673"/>
            <criterion comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36263"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36219"/>
            <criterion comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36444"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35110"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35478"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35875"/>
            <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35815"/>
            <criterion comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36470"/>
            <criterion comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36435"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:34668"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35191"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35384"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35413"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35465"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36292"/>
            <criterion comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36151"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35057"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35644"/>
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36198"/>
            <criterion comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35192"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36227"/>
            <criterion comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36087"/>
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36003"/>
            <criterion comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36374"/>
            <criterion comment="java-1.4.2-bea-demo is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36127"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35624"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35633"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35280"/>
            <criterion comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36290"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35256"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35453"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35822"/>
            <criterion comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36337"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35584"/>
            <criterion comment="java-1.4.2-bea-missioncontrol is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35296"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:34760"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35317"/>
            <criterion comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35972"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35429"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36350"/>
            <criterion comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36261"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35144"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35886"/>
            <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36301"/>
            <criterion comment="java-1.5.0-bea-missioncontrol is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36452"/>
            <criterion comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36372"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35437"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35392"/>
            <criterion comment="java-1.4.2-bea-src is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36128"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:34772"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9330" version="5" class="vulnerability">
      <metadata>
        <title>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0461"/>
        <description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:30.369-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:37.172-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:38.737-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9330 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:33.115-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:51.078-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30346"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30006"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30702"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30513"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30280"/>
          <criterion comment="kernel is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30056"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30508"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30654"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9329" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2360"/>
        <description>Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:56.990-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:36.210-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:37.782-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9329 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:41.079-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:49.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36946"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36579"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36881"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36895"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36542"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36866"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36934"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36951"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36973"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36756"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36632"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36469"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36368"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36851"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36740"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36985"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36805"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36754"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36734"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36918"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36499"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36402"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36931"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36752"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36976"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36867"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36115"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36794"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36943"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36905"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36908"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36685"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36662"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36309"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36944"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36641"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36607"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36651"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36977"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36939"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36385"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36979"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36933"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36742"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36873"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36932"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:35995"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-randr-source is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:37018"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36836"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36063"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36029"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36986"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36380"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36055"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36359"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9327" version="5" class="vulnerability">
      <metadata>
        <title>Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3547"/>
        <description>Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:30.003-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:35.536-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:37.152-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9327 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:01.298-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:49.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39593"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39549"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39548"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39554"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39686"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39415"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39557"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39560"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39587"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39607"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:38910"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39665"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39142"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39538"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39699"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39518"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39350"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39738"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39663"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39536"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39189"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39141"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39179"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9325" version="5" class="vulnerability">
      <metadata>
        <title>The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1522" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1522"/>
        <description>The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:08.618-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:35.249-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:36.801-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9325 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:39.181-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:48.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9323" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2701" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2701"/>
        <description>Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:36.592-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:34.736-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:36.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9323 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:52.604-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:48.055-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32169"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31729"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32242"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32151"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32014"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32144"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32068"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32248"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32293"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32244"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32012"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:31897"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32300"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32226"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32289"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32170"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32150"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32302"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32090"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32209"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9321" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in FreeType2 before 2.3.6 allows context-dependent attackers to execute arbitrary code via a crafted set of 16-bit length values within the Private dictionary table in a Printer Font Binary (PFB) file, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1806"/>
        <description>Integer overflow in FreeType2 before 2.3.6 allows context-dependent attackers to execute arbitrary code via a crafted set of 16-bit length values within the Private dictionary table in a Printer Font Binary (PFB) file, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:09.584-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:34.314-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:35.937-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9321 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:23.944-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:47.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-10.el3" test_ref="oval:org.mitre.oval:tst:36608"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-10.el3" test_ref="oval:org.mitre.oval:tst:36928"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:36978"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:37295"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:36877"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:37292"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37321"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37312"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37160"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9318" version="5" class="vulnerability">
      <metadata>
        <title>The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1562"/>
        <description>The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:56.860-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:33.959-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:35.636-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9318 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:19.364-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:47.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9317" version="5" class="vulnerability">
      <metadata>
        <title>CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2383"/>
        <description>CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:23.221-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:33.701-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:35.354-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9317 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:30.527-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:46.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xterm is earlier than 0:179-11.EL3" test_ref="oval:org.mitre.oval:tst:38121"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="xterm is earlier than 0:192-8.el4_7.2" test_ref="oval:org.mitre.oval:tst:37919"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="xterm is earlier than 0:215-5.el5_2.2" test_ref="oval:org.mitre.oval:tst:38031"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9315" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors.  NOTE: Vector 2 might also lead to a hang.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1561" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1561"/>
        <description>Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors.  NOTE: Vector 2 might also lead to a hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:05.445-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:33.407-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:35.007-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9315 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:40.386-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:46.007-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9314" version="5" class="vulnerability">
      <metadata>
        <title>libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3350" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3350"/>
        <description>libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:49.373-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:33.079-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:34.681-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9314 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:09:04.344-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:45.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libungif is earlier than 0:4.1.0-15.el3.3" test_ref="oval:org.mitre.oval:tst:32066"/>
            <criterion comment="libungif-devel is earlier than 0:4.1.0-15.el3.3" test_ref="oval:org.mitre.oval:tst:31940"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libungif is earlier than 0:4.1.3-1.el4.2" test_ref="oval:org.mitre.oval:tst:31956"/>
            <criterion comment="libungif-progs is earlier than 0:4.1.3-1.el4.2" test_ref="oval:org.mitre.oval:tst:32398"/>
            <criterion comment="libungif-devel is earlier than 0:4.1.3-1.el4.2" test_ref="oval:org.mitre.oval:tst:31871"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="giflib-devel is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38143"/>
            <criterion comment="giflib-utils is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38622"/>
            <criterion comment="giflib is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38639"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9313" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the WSP dissector in Ethereal 0.10.1 to 0.10.12 allows remote attackers to cause a denial of service or corrupt memory via unknown vectors that cause Ethereal to free an invalid pointer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3249" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3249"/>
        <description>Unspecified vulnerability in the WSP dissector in Ethereal 0.10.1 to 0.10.12 allows remote attackers to cause a denial of service or corrupt memory via unknown vectors that cause Ethereal to free an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:39.635-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:32.788-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:34.429-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9313 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:54.081-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:45.073-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32189"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32138"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32341"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32202"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9311" version="5" class="vulnerability">
      <metadata>
        <title>The seqfile handling (ip6fl_get_n function in ip6_flowlabel.c) in Linux kernel 2.6 up to 2.6.18-stable allows local users to cause a denial of service (hang or oops) via unspecified manipulations that trigger an infinite loop while searching for flowlabels.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5619" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5619"/>
        <description>The seqfile handling (ip6fl_get_n function in ip6_flowlabel.c) in Linux kernel 2.6 up to 2.6.18-stable allows local users to cause a denial of service (hang or oops) via unspecified manipulations that trigger an infinite loop while searching for flowlabels.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:04.377-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:32.505-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:34.139-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9311 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:22.132-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:44.646-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9310" version="5" class="vulnerability">
      <metadata>
        <title>The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0524"/>
        <description>The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:55.618-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:32.053-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:33.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9310 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:23.526-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:43.940-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31759"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:30948"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31858"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31704"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31679"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31505"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31329"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31673"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31737"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31787"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31830"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31383"/>
            <criterion comment="php is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31557"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31541"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31697"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31847"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31523"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31779"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31261"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31733"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9307" version="5" class="vulnerability">
      <metadata>
        <title>Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0815"/>
        <description>Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:36.138-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:31.629-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:33.218-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9307 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:12.811-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:43.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9306" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3076"/>
        <description>Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:57.303-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:31.009-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:32.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9306 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:22.710-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:42.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39378"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39359"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39036"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39270"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39397"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39118"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38466"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39389"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39088"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39081"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39351"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:38976"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el4" test_ref="oval:org.mitre.oval:tst:39195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39181"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39364"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39293"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39208"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39001"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39223"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39097"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39150"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39206"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9304" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5464"/>
        <description>Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:38.770-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:30.506-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:32.106-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9304 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:07.945-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:41.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32940"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33113"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32275"/>
            <criterion comment="seamonkey is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33128"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32259"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32596"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33188"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32780"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33131"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.5.el4" test_ref="oval:org.mitre.oval:tst:33198"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33241"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33268"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.8-0.1.el4" test_ref="oval:org.mitre.oval:tst:33216"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32752"/>
            <criterion comment="seamonkey is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32536"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32857"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.5.el4" test_ref="oval:org.mitre.oval:tst:33185"/>
            <criterion comment="firefox is earlier than 0:1.5.0.8-0.1.el4" test_ref="oval:org.mitre.oval:tst:33140"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33088"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33118"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33171"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32856"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33214"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9303" version="5" class="vulnerability">
      <metadata>
        <title>The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4045"/>
        <description>The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:15.342-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:30.237-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:31.766-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9303 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:23.669-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:41.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35491"/>
            <criterion comment="cups is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35533"/>
            <criterion comment="cups-libs is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:34735"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35537"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9302" version="5" class="vulnerability">
      <metadata>
        <title>Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1321"/>
        <description>Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:01.697-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:29.954-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:31.537-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9302 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:00.261-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:41.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="xen-libs is earlier than 0:3.0.3-25.0.4.el5" test_ref="oval:org.mitre.oval:tst:34182"/>
          <criterion comment="xen is earlier than 0:3.0.3-25.0.4.el5" test_ref="oval:org.mitre.oval:tst:33194"/>
          <criterion comment="xen-devel is earlier than 0:3.0.3-25.0.4.el5" test_ref="oval:org.mitre.oval:tst:34003"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9295" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:06.558-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:29.768-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:31.333-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9295 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:56.654-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:40.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="tar is earlier than 0:1.14-9.RHEL4" test_ref="oval:org.mitre.oval:tst:32074"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9291" version="5" class="vulnerability">
      <metadata>
        <title>The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0155" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0155"/>
        <description>The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:53.215-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:29.588-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:31.138-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9291 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:18.262-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:40.601-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="ipsec-tools is earlier than 0:0.2.5-0.4" test_ref="oval:org.mitre.oval:tst:30611"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9283" version="5" class="vulnerability">
      <metadata>
        <title>The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2102"/>
        <description>The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:40.438-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:29.369-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:30.872-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9283 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:07.306-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:40.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el3.3" test_ref="oval:org.mitre.oval:tst:32063"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el4.3" test_ref="oval:org.mitre.oval:tst:31738"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9280" version="5" class="vulnerability">
      <metadata>
        <title>Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3089"/>
        <description>Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:52.146-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:28.836-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:30.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9280 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:04.417-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:39.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32169"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31729"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32242"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32151"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32014"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32144"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32068"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32248"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32293"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32244"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32012"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:31897"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32300"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32226"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32289"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32170"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32150"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32302"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32090"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32209"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:928" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 OpenSSL Kerberos Handshake Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0112"/>
        <description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:59.729-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.352-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1543"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1542"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1541"/>
        <criterion comment="openssl096b version is less than 0.9.6b-16" negate="false" test_ref="oval:org.mitre.oval:tst:1540"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9279" version="5" class="vulnerability">
      <metadata>
        <title>PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1392" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1392"/>
        <description>PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:35.170-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:28.378-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:29.877-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9279 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:43.842-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:38.998-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31759"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:30948"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31858"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31704"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31679"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31505"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31329"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31673"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31737"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31787"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31830"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31383"/>
            <criterion comment="php is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31557"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31541"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31697"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31847"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31523"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31779"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31261"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31733"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9278" version="5" class="vulnerability">
      <metadata>
        <title>The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4000" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4000"/>
        <description>The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:55.413-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:28.143-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:29.571-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9278 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:43.546-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:38.662-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="krb5-workstation is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:34835"/>
          <criterion comment="krb5 is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:35134"/>
          <criterion comment="krb5-libs is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:34559"/>
          <criterion comment="krb5-server is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:35091"/>
          <criterion comment="krb5-devel is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:34927"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9270" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829"/>
        <description>Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:32.952-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:27.814-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:29.169-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9270 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:10.157-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:38.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:38258"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:38534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38635"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38709"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38670"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9262" version="5" class="vulnerability">
      <metadata>
        <title>Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2416"/>
        <description>Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:38.791-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:27.463-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:28.752-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9262 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:09.191-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:37.597-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-15" test_ref="oval:org.mitre.oval:tst:39096"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-15" test_ref="oval:org.mitre.oval:tst:39077"/>
            <criterion comment="libxml-devel is earlier than 1:1.8.17-9.3" test_ref="oval:org.mitre.oval:tst:38476"/>
            <criterion comment="libxml is earlier than 1:1.8.17-9.3" test_ref="oval:org.mitre.oval:tst:38526"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-15" test_ref="oval:org.mitre.oval:tst:39158"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.7" test_ref="oval:org.mitre.oval:tst:39083"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.7" test_ref="oval:org.mitre.oval:tst:38887"/>
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.7" test_ref="oval:org.mitre.oval:tst:39128"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.8" test_ref="oval:org.mitre.oval:tst:39183"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.8" test_ref="oval:org.mitre.oval:tst:38679"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.8" test_ref="oval:org.mitre.oval:tst:39178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9260" version="5" class="vulnerability">
      <metadata>
        <title>Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0078"/>
        <description>The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:55.973-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:27.246-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:28.516-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9260 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:23.701-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:37.274-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdebase is earlier than 6:3.1.3-5.8" test_ref="oval:org.mitre.oval:tst:31113"/>
          <criterion comment="kdebase-devel is earlier than 6:3.1.3-5.8" test_ref="oval:org.mitre.oval:tst:31092"/>
          <criterion comment="kdelibs is earlier than 6:3.1.3-6.9" test_ref="oval:org.mitre.oval:tst:30244"/>
          <criterion comment="kdelibs-devel is earlier than 6:3.1.3-6.9" test_ref="oval:org.mitre.oval:tst:30826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9257" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3120"/>
        <description>Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:51.725-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:26.983-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:28.282-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9257 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:34.879-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:36.892-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-11.1" test_ref="oval:org.mitre.oval:tst:31818"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-18.1" test_ref="oval:org.mitre.oval:tst:32386"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9256" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1839"/>
        <description>Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:31.549-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:26.732-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:27.970-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9256 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:02.715-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:36.484-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9254" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1797"/>
        <description>Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:35.750-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:26.330-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:27.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9254 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:40.980-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:35.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36023"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36184"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36260"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36208"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36311"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36459"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36349"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35927"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36419"/>
            <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36360"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36388"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35921"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36133"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9251" version="5" class="vulnerability">
      <metadata>
        <title>Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2875"/>
        <description>Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:50.971-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:25.944-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:27.238-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9251 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:42.188-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:35.425-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34804"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34557"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34837"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34795"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34562"/>
          <criterion comment="kernel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34357"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34379"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34873"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34870"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34374"/>
          <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9248" version="5" class="vulnerability">
      <metadata>
        <title>The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891"/>
        <description>The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:48.147-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:25.344-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:26.272-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9248 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:39.622-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:34.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39033"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:38392"/>
            <criterion comment="httpd is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39071"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39448"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39501"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:38802"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39716"/>
            <criterion comment="httpd is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39551"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38846"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38761"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38385"/>
            <criterion comment="httpd is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38816"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9241" version="5" class="vulnerability">
      <metadata>
        <title>nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776"/>
        <description>nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:06.871-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:24.802-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:25.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9241 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:47.218-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:34.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38413"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38419"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38110"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38217"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37995"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37833"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38347"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38410"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37953"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38386"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:37842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38355"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:38405"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38148"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38132"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38204"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38364"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38168"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:37685"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38372"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9240" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0761" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0761"/>
        <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:24.383-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:24.322-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:25.415-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9240 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:58.477-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:33.617-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30799"/>
          <criterion comment="mozilla is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30278"/>
          <criterion comment="mozilla-chat is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30755"/>
          <criterion comment="mozilla-mail is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30570"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30230"/>
          <criterion comment="mozilla-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30288"/>
          <criterion comment="mozilla-nss is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30323"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30339"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30813"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.2" test_ref="oval:org.mitre.oval:tst:30660"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9238" version="5" class="vulnerability">
      <metadata>
        <title>The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1431"/>
        <description>The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:27.164-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:24.129-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:25.207-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9238 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:57.140-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:33.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gnutls is earlier than 0:1.0.20-3.2.1" test_ref="oval:org.mitre.oval:tst:31862"/>
          <criterion comment="gnutls-devel is earlier than 0:1.0.20-3.2.1" test_ref="oval:org.mitre.oval:tst:31682"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9233" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the do_setlk function in fs/nfs/file.c in the Linux kernel before 2.6.26 allows local users to cause a denial of service (crash) via vectors resulting in an interrupted RPC call that leads to a stray FL_POSIX lock, related to improper handling of a race between fcntl and close in the EINTR case.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4307"/>
        <description>Race condition in the do_setlk function in fs/nfs/file.c in the Linux kernel before 2.6.26 allows local users to cause a denial of service (crash) via vectors resulting in an interrupted RPC call that leads to a stray FL_POSIX lock, related to improper handling of a race between fcntl and close in the EINTR case.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:10.304-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:23.592-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:24.666-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9233 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:38.991-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:32.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38437"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38348"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:37805"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38116"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38721"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38384"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38346"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38490"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38262"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38289"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38302"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38663"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38680"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38674"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38654"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38700"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38368"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38726"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38390"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38547"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38412"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38701"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38129"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9232" version="5" class="vulnerability">
      <metadata>
        <title>yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1439" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1439"/>
        <description>yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:01.362-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:23.372-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:24.424-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9232 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:47:12.010-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:32.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="rhn-check is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:40577"/>
          <criterion comment="rhn-setup is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:40438"/>
          <criterion comment="rhn-client-tools is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:39919"/>
          <criterion comment="rhn-setup-gnome is earlier than 0:0.4.20-33.el5_5.2" test_ref="oval:org.mitre.oval:tst:40563"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9231" version="5" class="vulnerability">
      <metadata>
        <title>The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1477" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1477"/>
        <description>The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:29.236-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:22.827-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:23.898-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9231 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:56.997-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:31.566-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31531"/>
            <criterion comment="mozilla is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31619"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31225"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31917"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31644"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31625"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31435"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31816"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31450"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31901"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31590"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.5" test_ref="oval:org.mitre.oval:tst:31571"/>
            <criterion comment="mozilla is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31860"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31894"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31245"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31913"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.5" test_ref="oval:org.mitre.oval:tst:31692"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31986"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31365"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31868"/>
            <criterion comment="firefox is earlier than 0:1.0.4-1.4.1" test_ref="oval:org.mitre.oval:tst:31311"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:30985"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31723"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9214" version="5" class="vulnerability">
      <metadata>
        <title>The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0115" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0115"/>
        <description>The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:06.750-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:22.592-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:23.648-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9214 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:46.094-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:31.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="device-mapper-multipath is earlier than 0:0.4.5-31.el4_7.1" test_ref="oval:org.mitre.oval:tst:38584"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kpartx is earlier than 0:0.4.7-23.el5_3.2" test_ref="oval:org.mitre.oval:tst:38470"/>
            <criterion comment="device-mapper-multipath is earlier than 0:0.4.7-23.el5_3.2" test_ref="oval:org.mitre.oval:tst:38587"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9210" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the hrtimer_forward function (hrtimer.c) in Linux kernel 2.6.21-rc4, when running on 64-bit systems, allows local users to cause a denial of service (infinite loop) via a timer with a large expiry value, which causes the timer to always be expired.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6712" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6712"/>
        <description>Integer overflow in the hrtimer_forward function (hrtimer.c) in Linux kernel 2.6.21-rc4, when running on 64-bit systems, allows local users to cause a denial of service (infinite loop) via a timer with a large expiry value, which causes the timer to always be expired.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:40.072-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:22.280-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:23.318-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9210 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:47:18.319-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:30.733-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36697"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36610"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36727"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:35799"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:35977"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36772"/>
          <criterion comment="kernel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36502"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36670"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36665"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:35765"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36539"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36637"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9209" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering a large number of open file descriptors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0948" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0948"/>
        <description>Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering a large number of open file descriptors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:15.007-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:21.990-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:23.011-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9209 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:59.777-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:30.425-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="krb5-workstation is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36272"/>
          <criterion comment="krb5 is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36493"/>
          <criterion comment="krb5-libs is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36531"/>
          <criterion comment="krb5-server is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36304"/>
          <criterion comment="krb5-devel is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36522"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9204" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003"/>
        <description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:05.187-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:21.715-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:22.711-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9204 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:06.392-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:30.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-BOOT is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30346"/>
          <criterion comment="kernel-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30006"/>
          <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30702"/>
          <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30513"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30280"/>
          <criterion comment="kernel is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30056"/>
          <criterion comment="kernel-source is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30508"/>
          <criterion comment="kernel-doc is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30654"/>
          <criterion comment="kernel-smp is earlier than 0:2.4.21-15.EL" test_ref="oval:org.mitre.oval:tst:30307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9202" version="5" class="vulnerability">
      <metadata>
        <title>Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5461"/>
        <description>Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:53.985-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:21.409-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:22.387-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9202 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:47:10.562-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:29.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:35985"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:35572"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:35569"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:35862"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:35936"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:35526"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:36099"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:35716"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:35676"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:35522"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" test_ref="oval:org.mitre.oval:tst:36027"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9201" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4141"/>
        <description>Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:17.944-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:21.069-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:22.002-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9201 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:21.422-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:28.710-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40050"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39464"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39090"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40063"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39443"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39703"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39080"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39862"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40057"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40029"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39849"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40039"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9200" version="5" class="vulnerability">
      <metadata>
        <title>The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of service (CPU consumption and error-message flood) by attempting to mount a crafted ext4 filesystem.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0747"/>
        <description>The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of service (CPU consumption and error-message flood) by attempting to mount a crafted ext4 filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:03.324-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:20.388-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:21.678-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9200 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:27.566-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:28.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38255"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38332"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39122"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39058"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39247"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39145"/>
          <criterion comment="kernel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38795"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38831"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38585"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39130"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38567"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39245"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9196" version="5" class="vulnerability">
      <metadata>
        <title>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365"/>
        <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:42.692-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:20.200-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:21.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9196 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:59.893-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:27.981-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ethereal-gnome is earlier than 0:0.10.3-0.30E.1" test_ref="oval:org.mitre.oval:tst:29720"/>
          <criterion comment="ethereal is earlier than 0:0.10.3-0.30E.1" test_ref="oval:org.mitre.oval:tst:30448"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9195" version="5" class="vulnerability">
      <metadata>
        <title>MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3781"/>
        <description>MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:49.264-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:19.913-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:21.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9195 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:33.996-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:27.646-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36197"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36749"/>
          <criterion comment="mysql-test is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36750"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36831"/>
          <criterion comment="mysql-server is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36646"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9191" version="5" class="vulnerability">
      <metadata>
        <title>Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813"/>
        <description>Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:53.942-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:19.625-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:20.885-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9191 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:10.096-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:27.204-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39162"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39589"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39603"/>
            <criterion comment="samba is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39658"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39633"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39222"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39493"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39205"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9188" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation errors."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6242"/>
        <description>Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation errors."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:10.337-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:19.383-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:20.601-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criterion comment="flash-plugin is earlier than 0:9.0.115.0-1.el3.with.oss" test_ref="oval:org.mitre.oval:tst:35926"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criterion comment="flash-plugin is earlier than 0:9.0.115.0-1.el4" test_ref="oval:org.mitre.oval:tst:35400"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criterion comment="flash-plugin is earlier than 0:9.0.115.0-1.el5" test_ref="oval:org.mitre.oval:tst:35776"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9187" version="5" class="vulnerability">
      <metadata>
        <title>Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0687" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0687"/>
        <description>Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:19.825-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:18.492-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:19.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9187 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:23.802-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:26.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30914"/>
          <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30029"/>
          <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30748"/>
          <criterion comment="XFree86-libs is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30779"/>
          <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30003"/>
          <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30783"/>
          <criterion comment="XFree86-twm is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30052"/>
          <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30925"/>
          <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:31001"/>
          <criterion comment="XFree86-doc is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30889"/>
          <criterion comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.4" test_ref="oval:org.mitre.oval:tst:30867"/>
          <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30841"/>
          <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30838"/>
          <criterion comment="openmotif is earlier than 0:2.2.3-4.RHEL3.4" test_ref="oval:org.mitre.oval:tst:31105"/>
          <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30875"/>
          <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30347"/>
          <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30599"/>
          <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30544"/>
          <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30612"/>
          <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30933"/>
          <criterion comment="XFree86-xdm is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30902"/>
          <criterion comment="XFree86-sdk is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30619"/>
          <criterion comment="XFree86 is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30899"/>
          <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30943"/>
          <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30747"/>
          <criterion comment="XFree86-xfs is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30145"/>
          <criterion comment="XFree86-tools is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30701"/>
          <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30805"/>
          <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30951"/>
          <criterion comment="openmotif-devel is earlier than 0:2.2.3-4.RHEL3.4" test_ref="oval:org.mitre.oval:tst:30744"/>
          <criterion comment="XFree86-xauth is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30843"/>
          <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30963"/>
          <criterion comment="XFree86-devel is earlier than 0:4.3.0-69.EL" test_ref="oval:org.mitre.oval:tst:30677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9185" version="5" class="vulnerability">
      <metadata>
        <title>The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0966" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0966"/>
        <description>The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:20.128-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:18.273-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:19.736-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9185 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:46.414-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:26.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el3" test_ref="oval:org.mitre.oval:tst:31686"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el4" test_ref="oval:org.mitre.oval:tst:31403"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9184" version="5" class="vulnerability">
      <metadata>
        <title>SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2447"/>
        <description>SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:39.893-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:18.098-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:19.538-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9184 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:48.479-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:25.849-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="spamassassin is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:32046"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9175" version="5" class="vulnerability">
      <metadata>
        <title>Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3628"/>
        <description>Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:41.723-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:17.770-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:19.160-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9175 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:53.256-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:25.479-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32882"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32738"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32917"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32447"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9173" version="5" class="vulnerability">
      <metadata>
        <title>lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4065" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4065"/>
        <description>lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:37.943-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:17.481-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:18.806-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9173 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:42.696-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:24.984-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-8.el3" test_ref="oval:org.mitre.oval:tst:35005"/>
            <criterion comment="libvorbis is earlier than 1:1.0-8.el3" test_ref="oval:org.mitre.oval:tst:35016"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.0-2.el4.5" test_ref="oval:org.mitre.oval:tst:34951"/>
            <criterion comment="libvorbis is earlier than 1:1.1.0-2.el4.5" test_ref="oval:org.mitre.oval:tst:34625"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5.0" test_ref="oval:org.mitre.oval:tst:35046"/>
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5.0" test_ref="oval:org.mitre.oval:tst:34551"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:917" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Mozilla Bypass Cookie Access Restrictions Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0594"/>
        <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.843-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false" test_ref="oval:org.mitre.oval:tst:1468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9167" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1741" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1741"/>
        <description>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:36.424-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:16.930-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:18.309-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9167 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:22.574-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:24.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9166" version="5" class="vulnerability">
      <metadata>
        <title>The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2692"/>
        <description>The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:02.684-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:16.702-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:18.057-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9166 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:52.861-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:24.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36197"/>
          <criterion comment="mysql-devel is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36749"/>
          <criterion comment="mysql-test is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36750"/>
          <criterion comment="mysql-bench is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36831"/>
          <criterion comment="mysql-server is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36646"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9165" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the KSSL Kernel Module May Lead to a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3470" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3470"/>
        <description>Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured with the KSSL proxy, allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors related to "memory buffers" of Secure Socket Layer (SSL) records.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-03T10:36:57.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-03T16:51:06.630-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.053-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102918" negate="false">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion comment="Patch 125100-10 or later installed" test_ref="oval:org.mitre.oval:tst:4665" negate="true"/>
            <criterion comment="Patch 121474-01 or later installed" test_ref="oval:org.mitre.oval:tst:4207" negate="false"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102918" negate="false">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion comment="Patch 125101-10 or later installed" test_ref="oval:org.mitre.oval:tst:4966" negate="true"/>
            <criterion comment="Patch 121475-01 or later installed" test_ref="oval:org.mitre.oval:tst:4240" negate="false"/>
          </criteria>
        </criteria>
        <criterion comment="kssl running" negate="false" test_ref="oval:org.mitre.oval:tst:4861"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9163" version="5" class="vulnerability">
      <metadata>
        <title>The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0607" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0607"/>
        <description>The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:52.072-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:16.519-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:17.820-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9163 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:38.962-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:23.741-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="ipsec-tools is earlier than 0:0.2.5-0.5" test_ref="oval:org.mitre.oval:tst:30435"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9161" version="5" class="vulnerability">
      <metadata>
        <title>components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0355"/>
        <description>components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:54.410-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:15.899-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:17.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9161 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:38.636-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:22.776-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38173"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38181"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38221"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38323"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38337"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:37355"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38135"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38326"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38186"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38184"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38228"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37943"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37433"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38309"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38278"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9157" version="5" class="vulnerability">
      <metadata>
        <title>jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which triggers an assertion failure related to the OBJ_IS_NATIVE function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5014"/>
        <description>jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which triggers an assertion failure related to the OBJ_IS_NATIVE function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:56.691-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:15.291-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:16.558-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9157 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:55.846-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:21.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9155" version="5" class="vulnerability">
      <metadata>
        <title>OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077"/>
        <description>OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:49.407-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:14.877-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:16.177-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9155 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:42.971-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:21.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.25" test_ref="oval:org.mitre.oval:tst:38011"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.25" test_ref="oval:org.mitre.oval:tst:37149"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.25" test_ref="oval:org.mitre.oval:tst:37990"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.49" test_ref="oval:org.mitre.oval:tst:38150"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_7.2" test_ref="oval:org.mitre.oval:tst:37921"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_7.2" test_ref="oval:org.mitre.oval:tst:38056"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.17.el4_7.2" test_ref="oval:org.mitre.oval:tst:37985"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-22.46.el4_7" test_ref="oval:org.mitre.oval:tst:37743"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl097a is earlier than 0:0.9.7a-9.el5_2.1" test_ref="oval:org.mitre.oval:tst:37259"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8b-10.el5_2.1" test_ref="oval:org.mitre.oval:tst:37599"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8b-10.el5_2.1" test_ref="oval:org.mitre.oval:tst:37285"/>
            <criterion comment="openssl is earlier than 0:0.9.8b-10.el5_2.1" test_ref="oval:org.mitre.oval:tst:37906"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9153" version="5" class="vulnerability">
      <metadata>
        <title>The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrated by an XSS attack that uses the kerberos parameter to the admin program, and leverages attribute injection and HTTP Parameter Pollution (HPP) issues.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2820"/>
        <description>The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrated by an XSS attack that uses the kerberos parameter to the admin program, and leverages attribute injection and HTTP Parameter Pollution (HPP) issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:34.178-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:14.651-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:15.754-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9153 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:23.201-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:21.008-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39673"/>
          <criterion comment="cups-devel is earlier than 1:1.3.7-11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39211"/>
          <criterion comment="cups is earlier than 1:1.3.7-11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39680"/>
          <criterion comment="cups-libs is earlier than 1:1.3.7-11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39517"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9151" version="5" class="vulnerability">
      <metadata>
        <title>The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0778"/>
        <description>The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:53.508-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:13.905-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:15.151-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9151 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:07.473-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:20.247-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9145" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5870"/>
        <description>Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:06.177-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:13.619-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:14.770-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9145 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:52.306-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:19.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-35.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33108"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-35.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32394"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-35.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33055"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-6.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33223"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-6.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33235"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-6.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33295"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-6.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9142" version="5" class="vulnerability">
      <metadata>
        <title>The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2698" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2698"/>
        <description>The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:38.799-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:12.949-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:14.154-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9142 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:25.612-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:18.955-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39011"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38739"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38992"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38800"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39114"/>
            <criterion comment="kernel is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39044"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39194"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38832"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38859"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39007"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38642"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38673"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39035"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38510"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38920"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39188"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39065"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39182"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39164"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38624"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39175"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38848"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39017"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38949"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39066"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38199"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39057"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39072"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38868"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39155"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38973"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38459"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9140" version="5" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0084"/>
        <description>Buffer overflow in the X11 dissector in Ethereal 0.8.10 through 0.10.8 allows remote attackers to execute arbitrary code via a crafted packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:16.367-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:12.678-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:13.850-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9140 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:00.002-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:18.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31265"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31097"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:914" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 S/MIME Protocol Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0564"/>
        <description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:51.518-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.016-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false" test_ref="oval:org.mitre.oval:tst:1468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9127" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the IP Implementation for Solaris 8 and 9 May Allow a Denial of Service</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2045"/>
        <description>Unspecified vulnerability in the IP implementation in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (CPU consumption) via crafted IP packets, probably related to fragmented packets with duplicate or missing fragments.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-06T11:39:14.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-08T21:33:23.689-04:00">DRAFT</status_change>
            <status_change date="2007-08-23T14:55:20.078-04:00">INTERIM</status_change>
            <status_change date="2007-09-10T14:45:27.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102866" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 116965-26 or later installed" test_ref="oval:org.mitre.oval:tst:4585" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102866" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 114344-25 or later installed" test_ref="oval:org.mitre.oval:tst:4736" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102866" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 116966-25 or later installed" test_ref="oval:org.mitre.oval:tst:4659" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102866" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 119435-15 or later installed" test_ref="oval:org.mitre.oval:tst:4750" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9124" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c.  NOTE: item 4 was originally identified by CVE-2006-2493.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1861" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1861"/>
        <description>Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c.  NOTE: item 4 was originally identified by CVE-2006-2493.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:04.611-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:12.380-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:13.550-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9124 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:25.873-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:18.121-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:37450"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38245"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38284"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38008"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38414"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38395"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38234"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38442"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9118" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the SMB dissector in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a buffer overflow or a denial of service (memory consumption) via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2365"/>
        <description>Unknown vulnerability in the SMB dissector in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a buffer overflow or a denial of service (memory consumption) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:27.474-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:12.134-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:13.297-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9118 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:09.449-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:17.669-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31966"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32076"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32122"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32035"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9117" version="5" class="vulnerability">
      <metadata>
        <title>Race condition between the kfree_skb and __skb_unlink functions in the socket buffer handling in Linux kernel 2.6.9, and possibly other versions, allows remote attackers to cause a denial of service (crash), as demonstrated using the TCP stress tests from the LTP test suite.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2446"/>
        <description>Race condition between the kfree_skb and __skb_unlink functions in the socket buffer handling in Linux kernel 2.6.9, and possibly other versions, allows remote attackers to cause a denial of service (crash), as demonstrated using the TCP stress tests from the LTP test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:52.196-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:11.828-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:12.961-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9117 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:52.742-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:17.249-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9111" version="5" class="vulnerability">
      <metadata>
        <title>The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0255"/>
        <description>String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:36.244-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:11.514-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:12.631-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9111 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:46.394-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:16.793-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31580"/>
          <criterion comment="mozilla is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31555"/>
          <criterion comment="thunderbird is earlier than 0:1.0.2-1.4.1" test_ref="oval:org.mitre.oval:tst:31382"/>
          <criterion comment="mozilla-chat is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31589"/>
          <criterion comment="mozilla-mail is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31583"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31421"/>
          <criterion comment="mozilla-nss is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31222"/>
          <criterion comment="mozilla-devel is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31447"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31579"/>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31131"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31380"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9108" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3106"/>
        <description>Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:02.087-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:11.257-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:12.365-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9108 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:08.145-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:16.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9106" version="5" class="vulnerability">
      <metadata>
        <title>The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0941"/>
        <description>The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:38.519-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:10.851-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:12.079-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9106 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:31.734-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:15.991-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-24.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31752"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-24.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31453"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-24.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31739"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-24.6.0.EL4" test_ref="oval:org.mitre.oval:tst:31617"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-24.6.0.EL4" test_ref="oval:org.mitre.oval:tst:31671"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.2-24.6.0.EL4" test_ref="oval:org.mitre.oval:tst:31138"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-24.6.0.EL4" test_ref="oval:org.mitre.oval:tst:31736"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9105" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3656" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3656"/>
        <description>Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:45.122-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:10.352-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:11.534-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9105 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:58.154-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:15.313-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:33986"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34827"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34839"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34762"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34814"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34694"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34925"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34723"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34968"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34971"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34868"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34492"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34775"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34828"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34981"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34335"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34957"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34608"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34810"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34667"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9101" version="5" class="vulnerability">
      <metadata>
        <title>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0580" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0580"/>
        <description>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:12.134-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:09.973-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:11.218-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9101 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:30.654-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:14.858-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38108"/>
          <criterion comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:37963"/>
          <criterion comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38333"/>
          <criterion comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38944"/>
          <criterion comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38805"/>
          <criterion comment="tomcat5 is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38688"/>
          <criterion comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38891"/>
          <criterion comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38239"/>
          <criterion comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38824"/>
          <criterion comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38955"/>
          <criterion comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38428"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9100" version="3" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with a large size value in the RA header.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2264" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2264"/>
        <description>Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with a large size value in the RA header.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:29.465-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:09.726-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:10.918-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criterion comment="realplayer is earlier than 0:10.0.9-0.rhel3.4" test_ref="oval:org.mitre.oval:tst:34710"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criterion comment="RealPlayer is earlier than 0:10.0.9-2" test_ref="oval:org.mitre.oval:tst:34808"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criterion comment="RealPlayer is earlier than 0:10.0.9-3.el5" test_ref="oval:org.mitre.oval:tst:35065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:91" version="3" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE ToolTalk Database Null Write Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Common Desktop Environment</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0677"/>
        <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:28.035-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:08.816-04:00">ACCEPTED</status_change>
            <modified comment="Fixed incorrect user_id element value in process_state.  Incorrect value was 'root', updated to value of '0'." date="2010-09-02T15:11:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T15:13:53.948-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:46.125-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 107893-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2969"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9080" version="5" class="vulnerability">
      <metadata>
        <title>The auto-reap of child processes in Linux kernel 2.6 before 2.6.15 includes processes with ptrace attached, which leads to a dangling ptrace reference and allows local users to cause a denial of service (crash) and gain root privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3784"/>
        <description>The auto-reap of child processes in Linux kernel 2.6 before 2.6.15 includes processes with ptrace attached, which leads to a dangling ptrace reference and allows local users to cause a denial of service (crash) and gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:36.965-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:09.474-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:10.623-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9080 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:12.473-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:14.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9079" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.12.5 does not properly destroy a keyring that is not instantiated properly, which allows local users or remote attackers to cause a denial of service (kernel oops) via a keyring with a payload that is not empty, which causes the creation to fail, leading to a null dereference in the keyring destructor.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2099"/>
        <description>The Linux kernel before 2.6.12.5 does not properly destroy a keyring that is not instantiated properly, which allows local users or remote attackers to cause a denial of service (kernel oops) via a keyring with a payload that is not empty, which causes the creation to fail, leading to a null dereference in the keyring destructor.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:48.408-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:09.219-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:10.353-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9079 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:59.421-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:14.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9076" version="5" class="vulnerability">
      <metadata>
        <title>The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2957" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2957"/>
        <description>The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:00.998-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:08.737-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:09.881-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9076 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:29.130-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:13.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37980"/>
            <criterion comment="libpurple is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37625"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37827"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37120"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37969"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:38038"/>
            <criterion comment="finch is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37822"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:38119"/>
            <criterion comment="pidgin is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:38052"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:38103"/>
            <criterion comment="libpurple is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:38090"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37997"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:38020"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37865"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37809"/>
            <criterion comment="finch is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37973"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:38050"/>
            <criterion comment="pidgin-docs is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37775"/>
            <criterion comment="pidgin is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37838"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9071" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1704"/>
        <description>Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:13.252-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:08.389-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:09.527-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9071 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:25.607-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:12.848-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="elfutils-libelf-devel is earlier than 0:0.94.1-2" test_ref="oval:org.mitre.oval:tst:32457"/>
            <criterion comment="binutils is earlier than 0:2.14.90.0.4-39" test_ref="oval:org.mitre.oval:tst:31731"/>
            <criterion comment="elfutils-libelf is earlier than 0:0.94.1-2" test_ref="oval:org.mitre.oval:tst:32656"/>
            <criterion comment="elfutils-devel is earlier than 0:0.94.1-2" test_ref="oval:org.mitre.oval:tst:32533"/>
            <criterion comment="elfutils is earlier than 0:0.94.1-2" test_ref="oval:org.mitre.oval:tst:32396"/>
            <criterion comment="gdb is earlier than 0:6.3.0.0-1.62" test_ref="oval:org.mitre.oval:tst:29887"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="elfutils-libelf-devel is earlier than 0:0.97.1-3" test_ref="oval:org.mitre.oval:tst:32684"/>
            <criterion comment="binutils is earlier than 0:2.15.92.0.2-15" test_ref="oval:org.mitre.oval:tst:31192"/>
            <criterion comment="elfutils-libelf is earlier than 0:0.97.1-3" test_ref="oval:org.mitre.oval:tst:31848"/>
            <criterion comment="elfutils-devel is earlier than 0:0.97.1-3" test_ref="oval:org.mitre.oval:tst:32660"/>
            <criterion comment="elfutils is earlier than 0:0.97.1-3" test_ref="oval:org.mitre.oval:tst:32629"/>
            <criterion comment="gdb is earlier than 0:6.3.0.0-1.63" test_ref="oval:org.mitre.oval:tst:32136"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9067" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the custom tag support for the TIFF library (libtiff) before 3.8.2 allows remote attackers to cause a denial of service (instability or crash) and execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3465"/>
        <description>Unspecified vulnerability in the custom tag support for the TIFF library (libtiff) before 3.8.2 allows remote attackers to cause a denial of service (instability or crash) and execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:00.520-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:08.120-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:09.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9067 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:13.834-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:12.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:32819"/>
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32069"/>
            <criterion comment="kdegraphics is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:33012"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32843"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32922"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9063" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5024"/>
        <description>Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:08.912-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:07.409-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:08.374-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9063 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:58.999-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:11.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9058" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0396"/>
        <description>Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:05.504-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:07.219-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:08.179-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9058 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:47.705-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:11.312-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criterion comment="cvs is earlier than 0:1.11.2-22" test_ref="oval:org.mitre.oval:tst:30644"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9053" version="5" class="vulnerability">
      <metadata>
        <title>The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4571"/>
        <description>The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:14.491-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:06.665-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:07.641-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9053 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:39.340-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:10.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35219"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35593"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35357"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35021"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35284"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35088"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:34595"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35139"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35215"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35555"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35511"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35474"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35543"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:905" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Ethereal Denial of Service via 0-Length Presentation Protocol Selector</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0367"/>
        <description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.816-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:08.565-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1505"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1504"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9048" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6111"/>
        <description>Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:04.609-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:06.367-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:07.339-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9048 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:23.826-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:10.193-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9040" version="5" class="vulnerability">
      <metadata>
        <title>The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0135"/>
        <description>The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:47.652-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:05.902-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:06.894-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9040 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:07.964-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:09.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9039" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 10 Systems May Panic or Hang When Running Certain DTrace D Programs</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4126"/>
        <description>Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-02T11:47:26.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-03T16:50:57.753-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.800-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.047-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103021" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-10 or later installed" test_ref="oval:org.mitre.oval:tst:4221" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103021" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-10 or later installed" test_ref="oval:org.mitre.oval:tst:4704" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9020" version="5" class="vulnerability">
      <metadata>
        <title>The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3145" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3145"/>
        <description>The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:47.309-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:05.610-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:06.232-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9020 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:14.859-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:09.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:902" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL Improper Unknown Message Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0081"/>
        <description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.007-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:08.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9005" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1373"/>
        <description>Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:52.754-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:05.140-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:05.736-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9005 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:29.401-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:08.466-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="pidgin is earlier than 0:1.5.1-3.el3" test_ref="oval:org.mitre.oval:tst:38766"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38580"/>
            <criterion comment="libpurple is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38729"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38659"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38675"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38361"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38431"/>
            <criterion comment="finch is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38593"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38640"/>
            <criterion comment="pidgin is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38775"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38564"/>
            <criterion comment="libpurple is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38579"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38686"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38687"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38223"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38606"/>
            <criterion comment="finch is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38749"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38576"/>
            <criterion comment="pidgin is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38730"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9004" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4484" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4484"/>
        <description>Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:38.944-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:04.556-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:05.178-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9004 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:15.824-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:07.650-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32928"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32870"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32829"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32485"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32258"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32491"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32860"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32175"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32788"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33059"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32876"/>
            <criterion comment="php is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32754"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33047"/>
            <criterion comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:35731"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33052"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32964"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32700"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32272"/>
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32985"/>
            <criterion comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36408"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32808"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32962"/>
            <criterion comment="gd is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36386"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32483"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36297"/>
            <criterion comment="gd-devel is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36448"/>
            <criterion comment="gd-progs is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35759"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9" version="4" class="vulnerability">
      <metadata>
        <title>Solaris 8 RPC xdr_array Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>libnsl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391"/>
        <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:40.134-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:14:00.967-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:14:45.096-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:08.069-04:00">ACCEPTED</status_change>
            <modified comment="Fixed incorrect user_id element value in process_state.  Incorrect value was 'root', updated to value of '0'." date="2010-09-02T15:11:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T15:13:53.086-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:45.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criteria operator="OR" comment="rpc.cmsd or dmispd exist">
            <criterion comment="File rpc.cmsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3140"/>
            <criterion comment="File dmispd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3139"/>
          </criteria>
          <criteria operator="AND" comment="Patches 108827-30 and 108901-06" negate="true">
            <criterion comment="Patch 108827-30 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3138"/>
            <criterion comment="Patch 108901-06 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3137"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="rpc.cmsd enabled OR dmispd running">
            <criteria operator="AND" comment="rpc.cmsd enabled">
              <criterion comment="inetd.conf contains rpc.cmsd" negate="false" test_ref="oval:org.mitre.oval:tst:3136"/>
              <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
              <criteria operator="OR" comment="File rpc.cmsd executable">
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3134"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3133"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3132"/>
              </criteria>
            </criteria>
            <criterion comment="dmispd running" negate="false" test_ref="oval:org.mitre.oval:tst:3131"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8996" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in Python before 2.5.2 might allow context-dependent attackers to have an unknown impact via vectors related to (1) Include/pymem.h; (2) _csv.c, (3) _struct.c, (4) arraymodule.c, (5) audioop.c, (6) binascii.c, (7) cPickle.c, (8) cStringIO.c, (9) cjkcodecs/multibytecodec.c, (10) datetimemodule.c, (11) md5.c, (12) rgbimgmodule.c, and (13) stropmodule.c in Modules/; (14) bufferobject.c, (15) listobject.c, and (16) obmalloc.c in Objects/; (17) Parser/node.c; and (18) asdl.c, (19) ast.c, (20) bltinmodule.c, and (21) compile.c in Python/, as addressed by "checks for integer overflows, contributed by Google."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3143"/>
        <description>Multiple integer overflows in Python before 2.5.2 might allow context-dependent attackers to have an unknown impact via vectors related to (1) Include/pymem.h; (2) _csv.c, (3) _struct.c, (4) arraymodule.c, (5) audioop.c, (6) binascii.c, (7) cPickle.c, (8) cStringIO.c, (9) cjkcodecs/multibytecodec.c, (10) datetimemodule.c, (11) md5.c, (12) rgbimgmodule.c, and (13) stropmodule.c in Modules/; (14) bufferobject.c, (15) listobject.c, and (16) obmalloc.c in Objects/; (17) Parser/node.c; and (18) asdl.c, (19) ast.c, (20) bltinmodule.c, and (21) compile.c in Python/, as addressed by "checks for integer overflows, contributed by Google."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:06.152-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:04.157-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:04.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8996 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:15.932-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:07.005-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38704"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38695"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38872"/>
            <criterion comment="python is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38617"/>
            <criterion comment="python-docs is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:37965"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38916"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38703"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38787"/>
            <criterion comment="python is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38939"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38889"/>
            <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38958"/>
            <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38827"/>
            <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8994" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0529"/>
        <description>Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:20.926-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:03.719-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:04.441-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8994 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:53.366-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:06.635-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
          <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8992" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions.  NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885).  NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0906"/>
        <description>Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions.  NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885).  NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:30.268-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:02.968-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:03.653-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8992 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:43.245-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:05.722-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:899" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX 11.04 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:54.417-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:01.065-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:23:00.955-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:23:41.998-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:28.351-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.562-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.792-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:899 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:58.073-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:48.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
          <criteria operator="AND" comment="700 Series OS Release 11.04">
            <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04">
            <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="Patch PHNE_33427 is installed" test_ref="oval:org.mitre.oval:tst:3468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8978" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2361" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2361"/>
        <description>Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:45.717-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:01.661-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:02.694-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8978 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:13.119-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:04.559-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36946"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36579"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36881"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36895"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36542"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36866"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36934"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36951"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36973"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36756"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36632"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36469"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36368"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36851"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36740"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36985"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36805"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36754"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36734"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36918"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36499"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36402"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36931"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36752"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36976"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36867"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36115"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36794"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36943"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36905"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36908"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36685"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36662"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36309"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36944"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36641"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36607"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36651"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36977"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36939"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36385"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36979"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36933"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36742"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36873"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36932"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:35995"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-randr-source is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:37018"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36836"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36063"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36029"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36986"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36380"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36055"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36359"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8969" version="5" class="vulnerability">
      <metadata>
        <title>Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working directory or (2) a certain subdirectory of the current working directory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3894"/>
        <description>Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working directory or (2) a certain subdirectory of the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:56.239-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:01.464-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:02.494-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8969 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:41:00.978-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:43:29.963-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:04.244-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criterion comment="dstat is earlier than 0:0.6.6-3.el5_4.1" test_ref="oval:org.mitre.oval:tst:39568"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8968" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0238"/>
        <description>Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:45.986-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:00.206-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:01.225-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8968 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:51.318-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:02.630-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-38.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33440"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-38.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33125"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-38.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33421"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33334"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33202"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33265"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33436"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33388"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33424"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33485"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33323"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33367"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33452"/>
            <criterion comment="openoffice.org is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33446"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33301"/>
            <criterion comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33679"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33157"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33463"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33142"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33606"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33009"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33302"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33387"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33013"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33611"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33638"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33048"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33513"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33756"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33355"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33147"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33448"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33749"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33529"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33254"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33659"/>
            <criterion comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33060"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33039"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33271"/>
            <criterion comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33389"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33476"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33477"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33051"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33313"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33511"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:32740"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33552"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33490"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33514"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33365"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33599"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33533"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33023"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33160"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33553"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33401"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33480"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33168"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33643"/>
            <criterion comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33451"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33201"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33486"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:32762"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33450"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33579"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33544"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33358"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33604"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33212"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33377"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33364"/>
            <criterion comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33111"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33324"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33471"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33420"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33670"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:32682"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33543"/>
            <criterion comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33517"/>
            <criterion comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33393"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33484"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8966" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1379"/>
        <description>Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:16.195-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:59.257-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:00.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8966 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:48.747-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:00.918-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36946"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36579"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36881"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36895"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36542"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36866"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36934"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36951"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36973"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36756"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36632"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36469"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36368"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36851"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36740"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36985"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36805"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36754"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36734"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36918"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36499"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36402"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36931"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36752"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36976"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36867"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36115"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36794"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36943"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36905"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36908"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36685"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36662"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36309"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36944"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36641"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36607"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36651"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36977"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36939"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36385"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36979"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36933"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36742"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36873"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36932"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:35995"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-randr-source is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:37018"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36836"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36063"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36029"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36986"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36380"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36055"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36359"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8944" version="5" class="vulnerability">
      <metadata>
        <title>fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0269"/>
        <description>fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:15.884-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:58.875-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:59.877-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8944 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:53.540-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:00.476-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38113"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38107"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38167"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38064"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38380"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:37672"/>
          <criterion comment="kernel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38093"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38127"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38109"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38430"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:37764"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38397"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8931" version="5" class="vulnerability">
      <metadata>
        <title>GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0578" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0578"/>
        <description>GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:55.796-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:58.639-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:59.636-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8931 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:49.858-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:00.135-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="NetworkManager-gnome is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:38177"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:38557"/>
          <criterion comment="NetworkManager-glib is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:38175"/>
          <criterion comment="NetworkManager-devel is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:38098"/>
          <criterion comment="NetworkManager is earlier than 1:0.7.0-4.el5_3" test_ref="oval:org.mitre.oval:tst:38451"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8920" version="5" class="vulnerability">
      <metadata>
        <title>The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel data or cause a denial of service (crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6417"/>
        <description>The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel data or cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:08.667-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:58.321-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:59.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8920 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:46:34.211-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:59.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37589"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37288"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37600"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37692"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37104"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37681"/>
          <criterion comment="kernel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37688"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37710"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37698"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37703"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37665"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37649"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8916" version="5" class="vulnerability">
      <metadata>
        <title>The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0063"/>
        <description>The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:11.357-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:57.885-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:58.850-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8916 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:45.662-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:59.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36272"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36493"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36531"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36304"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36522"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36541"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36418"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36371"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36482"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36318"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36285"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36069"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36233"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36199"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:891" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Ethereal Denial of Service via Malformed RADIUS Packet</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365"/>
        <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:20.992-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:07.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1505"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1504"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8896" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0803"/>
        <description>Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:03.181-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:57.571-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:58.425-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8896 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:34.296-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:58.649-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="tetex-latex is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31559"/>
          <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.7" test_ref="oval:org.mitre.oval:tst:30890"/>
          <criterion comment="libtiff is earlier than 0:3.5.7-20.1" test_ref="oval:org.mitre.oval:tst:31042"/>
          <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31693"/>
          <criterion comment="kdegraphics is earlier than 7:3.1.3-3.7" test_ref="oval:org.mitre.oval:tst:31096"/>
          <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31615"/>
          <criterion comment="tetex is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31603"/>
          <criterion comment="libtiff-devel is earlier than 0:3.5.7-20.1" test_ref="oval:org.mitre.oval:tst:31022"/>
          <criterion comment="tetex-afm is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31685"/>
          <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31747"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8888" version="5" class="vulnerability">
      <metadata>
        <title>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-0689.  Reason: This candidate is a duplicate of CVE-2009-0689.  Certain codebase relationships were not originally clear.  Notes: All CVE users should reference CVE-2009-0689 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1563"/>
        <description>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-0689.  Reason: This candidate is a duplicate of CVE-2009-0689.  Certain codebase relationships were not originally clear.  Notes: All CVE users should reference CVE-2009-0689 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:34.973-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:56.979-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:57.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8888 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:44.345-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:57.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39570"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39466"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39720"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39691"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39583"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39727"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39575"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39481"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39675"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39683"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39031"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39547"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39753"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8884" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0290" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0290"/>
        <description>Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:51.664-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:56.706-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:57.555-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8884 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:14.969-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:57.373-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="bind-utils is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:40044"/>
          <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39542"/>
          <criterion comment="bind-devel is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39904"/>
          <criterion comment="bind-chroot is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39693"/>
          <criterion comment="caching-nameserver is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39892"/>
          <criterion comment="bind-sdb is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:40054"/>
          <criterion comment="bind is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39489"/>
          <criterion comment="bind-libs is earlier than 30:9.3.6-4.P1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39885"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8880" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "javascript" sequence, aka "HTML escaped low surrogates bug."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4066" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4066"/>
        <description>Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&amp;#56325ascript" sequence, aka "HTML escaped low surrogates bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:22.936-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:56.240-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:57.063-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8880 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:24.188-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:56.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8872" version="5" class="vulnerability">
      <metadata>
        <title>The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4308"/>
        <description>The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:46.912-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:55.587-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:56.417-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8872 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:02.975-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:55.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35660"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35620"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35663"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35627"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35653"/>
            <criterion comment="kernel is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35769"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35035"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35699"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:34809"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35330"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35339"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35337"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35227"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35043"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35276"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:34448"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35366"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35208"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35326"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35345"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:887" version="2" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in Red Hat Enterprise 3 Ethereal</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176"/>
        <description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:37.108-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:07.514-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1505"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1504"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8850" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5962" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5962"/>
        <description>Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:32.364-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:55.401-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:56.222-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8850 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:54.367-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:55.546-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criterion comment="vsftpd is earlier than 0:2.0.5-12.el5" test_ref="oval:org.mitre.oval:tst:36561"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8844" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1096"/>
        <description>Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:13.253-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:55.174-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:55.934-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8844 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:41.675-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:55.198-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:38276"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:37661"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:37652"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:37769"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-0.30.b09.el5" test_ref="oval:org.mitre.oval:tst:38561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8843" version="5" class="vulnerability">
      <metadata>
        <title>Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0817"/>
        <description>Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:45.674-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:54.909-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:55.731-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8843 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:16.851-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:54.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL3 or CentOS3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="imlib is earlier than 1:1.9.13-13.3" test_ref="oval:org.mitre.oval:tst:30862"/>
          <criterion comment="imlib-devel is earlier than 1:1.9.13-13.3" test_ref="oval:org.mitre.oval:tst:30970"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8841" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657026.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3882"/>
        <description>Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657026.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:54.796-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:54.684-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:55.490-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8841 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:30.622-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:54.534-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:38878"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39616"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39115"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39531"/>
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.7.b09.el5" test_ref="oval:org.mitre.oval:tst:39655"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8833" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2335" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2335"/>
        <description>Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:01.150-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:54.466-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:55.259-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8833 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:30.953-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:54.184-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.0-3.el3.2" test_ref="oval:org.mitre.oval:tst:31634"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.5-6.el4.2" test_ref="oval:org.mitre.oval:tst:32163"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:881" version="2" class="vulnerability">
      <metadata>
        <title>Bourne Shell Local-DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1780"/>
        <description>The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-14T06:41:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-19T10:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-10T08:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed criterion to check for the patch or later being installed instead of simply checking if the patch is installed." date="2009-07-17T11:04:00.601-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:07:21.610-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:04.542-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109324-09 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1520"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118535-03 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1519"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 121004-01 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1518"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109325-09 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1517"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118536-03 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1516"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 121005-01 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1515"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:880" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Ethereal Denial of Service via 0-Length Presentation Protocol Selector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0367"/>
        <description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.508-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:07.190-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:88" version="4" class="vulnerability">
      <metadata>
        <title>Ethereal SPNEGO Dissector Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0430" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0430"/>
        <description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.658-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.986-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:88 - Typo Corrections" date="2014-05-22T11:01:00.943-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:03:38.946-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:50.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Red Hat 9 is installed" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:879" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Ethereal Denial of Service via Malformed RADIUS Packet</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365"/>
        <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.657-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.701-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:878" version="2" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in Red Hat Ethereal</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176"/>
        <description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:37.429-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8778" version="5" class="vulnerability">
      <metadata>
        <title>The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0176"/>
        <description>The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:29.507-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:54.071-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:54.809-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8778 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:58.932-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:53.609-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31870"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31657"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31642"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31984"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31213"/>
            <criterion comment="kernel is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31839"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31941"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31760"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31960"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:877" version="4" class="vulnerability">
      <metadata>
        <title>Red Hat Squid ACL Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0189"/>
        <description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.363-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.268-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.366-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T21:00:44.076-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:45.311-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="squid version is less than 2.5STABLE1-3.9" negate="false" test_ref="oval:org.mitre.oval:tst:1533"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8768" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1722"/>
        <description>Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:44.986-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:53.535-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:54.458-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8768 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:09.571-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:53.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.17-13.3.53" test_ref="oval:org.mitre.oval:tst:36975"/>
            <criterion comment="cups is earlier than 0:1.1.17-13.3.53" test_ref="oval:org.mitre.oval:tst:36705"/>
            <criterion comment="cups-libs is earlier than 0:1.1.17-13.3.53" test_ref="oval:org.mitre.oval:tst:36751"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_6.8" test_ref="oval:org.mitre.oval:tst:36818"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_6.8" test_ref="oval:org.mitre.oval:tst:36974"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_6.8" test_ref="oval:org.mitre.oval:tst:36816"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 0:1.2.4-11.18.el5_2.1" test_ref="oval:org.mitre.oval:tst:36736"/>
            <criterion comment="cups-devel is earlier than 0:1.2.4-11.18.el5_2.1" test_ref="oval:org.mitre.oval:tst:36909"/>
            <criterion comment="cups is earlier than 0:1.2.4-11.18.el5_2.1" test_ref="oval:org.mitre.oval:tst:36512"/>
            <criterion comment="cups-libs is earlier than 0:1.2.4-11.18.el5_2.1" test_ref="oval:org.mitre.oval:tst:36915"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8765" version="5" class="vulnerability">
      <metadata>
        <title>Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5086"/>
        <description>Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:00.484-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:53.329-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:54.240-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8765 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:44:00.576-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:47:13.437-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:52.700-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="libvirt-python is earlier than 0:0.3.3-14.el5_3.1" test_ref="oval:org.mitre.oval:tst:38518"/>
          <criterion comment="libvirt is earlier than 0:0.3.3-14.el5_3.1" test_ref="oval:org.mitre.oval:tst:38026"/>
          <criterion comment="libvirt-devel is earlier than 0:0.3.3-14.el5_3.1" test_ref="oval:org.mitre.oval:tst:38242"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:876" version="4" class="vulnerability">
      <metadata>
        <title>Apache 2 Denial of Service due to Memory Leak in mod_ssl</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>httpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0113"/>
        <description>Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:31.325-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.035-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.470-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T21:00:00.400-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:44.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_ssl version is less than 2.0.46-32.ent" negate="false" test_ref="oval:org.mitre.oval:tst:1534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8758" version="3" class="vulnerability">
      <metadata>
        <title>Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 3</platform>
          <platform>Red Hat Enterprise Linux Extras 4</platform>
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5239" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5239"/>
        <description>Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:38.700-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:52.243-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:53.126-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="redhat-release is version 3" test_ref="oval:org.mitre.oval:tst:30337"/>
          <criteria operator="OR">
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:35438"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:36312"/>
            <criterion comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.1.el3" test_ref="oval:org.mitre.oval:tst:36020"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:36170"/>
            <criterion comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.1.el3" test_ref="oval:org.mitre.oval:tst:36131"/>
            <criterion comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.1.el3" test_ref="oval:org.mitre.oval:tst:35578"/>
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:35718"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:36338"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.10-1jpp.2.el3" test_ref="oval:org.mitre.oval:tst:35439"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 4" test_ref="oval:org.mitre.oval:tst:29709"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35617"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:34688"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35272"/>
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35892"/>
            <criterion comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35850"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:34849"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36357"/>
            <criterion comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36067"/>
            <criterion comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35854"/>
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35532"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35673"/>
            <criterion comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36263"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36219"/>
            <criterion comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36444"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35110"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35478"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35875"/>
            <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35815"/>
            <criterion comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36470"/>
            <criterion comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36435"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:34668"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35191"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35384"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35413"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.6-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:35465"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.10-1jpp.2.el4" test_ref="oval:org.mitre.oval:tst:36292"/>
            <criterion comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:36151"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.13-1jpp.1.el4" test_ref="oval:org.mitre.oval:tst:35057"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
          <criteria operator="OR">
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35644"/>
            <criterion comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36198"/>
            <criterion comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35192"/>
            <criterion comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36227"/>
            <criterion comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36087"/>
            <criterion comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36003"/>
            <criterion comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36374"/>
            <criterion comment="java-1.4.2-bea-demo is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36127"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35624"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35633"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35280"/>
            <criterion comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36290"/>
            <criterion comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35256"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35453"/>
            <criterion comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35822"/>
            <criterion comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36337"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35584"/>
            <criterion comment="java-1.4.2-bea-missioncontrol is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35296"/>
            <criterion comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:34760"/>
            <criterion comment="java-1.5.0-sun is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35317"/>
            <criterion comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35972"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35429"/>
            <criterion comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36350"/>
            <criterion comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36261"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.6-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35144"/>
            <criterion comment="java-1.4.2-ibm is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:35886"/>
            <criterion comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.10-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:36301"/>
            <criterion comment="java-1.5.0-bea-missioncontrol is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36452"/>
            <criterion comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36372"/>
            <criterion comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35437"/>
            <criterion comment="java-1.5.0-sun-src is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:35392"/>
            <criterion comment="java-1.4.2-bea-src is earlier than 0:1.4.2.16-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36128"/>
            <criterion comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.13-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:34772"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8757" version="5" class="vulnerability">
      <metadata>
        <title>GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0779"/>
        <description>GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:03.340-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:51.570-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:52.447-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8757 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:29.311-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:51.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:875" version="2" class="vulnerability">
      <metadata>
        <title>XMLSoft Libxml2 Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>libxml2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0110"/>
        <description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-22T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.480-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.843-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="libxml2 version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1609"/>
          <criterion comment="libxml2-devel version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1608"/>
          <criterion comment="libxml2-python version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1607"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:874" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Mozilla Zombie Document Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0191"/>
        <description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.329-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mozilla version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1538"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mozilla is executable">
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1537"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1536"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1535"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:873" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Mozilla Bypass Cookie Access Restrictions Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0594"/>
        <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.788-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.449-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mozilla version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1538"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mozilla is executable">
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1537"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1536"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1535"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:872" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat S/MIME Protocol Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0564"/>
        <description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.006-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.158-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1539"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8717" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217"/>
        <description>The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:17.264-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:51.843-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:34.551-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:01.404-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:04.407-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:14.879-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:39.618-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:31.509-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:41.445-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:871" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 OpenSSL Improper Unknown Message Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0081"/>
        <description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:42.840-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.958-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1543"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1542"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1541"/>
        <criterion comment="openssl096b version is less than 0.9.6b-16" negate="false" test_ref="oval:org.mitre.oval:tst:1540"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:870" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 OpenSSL do_change_cipher_spec Function Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:46.147-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1543"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1542"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1541"/>
        <criterion comment="openssl096b version is less than 0.9.6b-16" negate="false" test_ref="oval:org.mitre.oval:tst:1540"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:869" version="4" class="vulnerability">
      <metadata>
        <title>Net-SNMP MIB Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Net-SNMP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0935" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0935"/>
        <description>Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:40.441-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.539-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.706-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T21:00:30.287-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:44.564-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="net-snmp version is less than 5.0.9-2.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1545"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="snmpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1544"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8687" version="5" class="vulnerability">
      <metadata>
        <title>A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0729" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0729"/>
        <description>A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:07.998-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:51.245-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:52.121-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8687 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:05.326-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:50.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40272"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40483"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40310"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40062"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40096"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39895"/>
          <criterion comment="kernel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40165"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40131"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40380"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39955"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40115"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8686" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3794"/>
        <description>Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.581-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:50.163-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:33.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8680" version="5" class="vulnerability">
      <metadata>
        <title>The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1388"/>
        <description>The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:58.917-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:50.892-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:51.730-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8680 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:47:00.450-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:50:20.899-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:50.472-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38128"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38668"/>
          <criterion comment="kernel-xen is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38883"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38948"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38732"/>
          <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38969"/>
          <criterion comment="kernel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38991"/>
          <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:39056"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38817"/>
          <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:39009"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38672"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38983"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:868" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel eflags Checking Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0001"/>
        <description>Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:1547"/>
        <criterion comment="kernel version is less than 2.4.21-9.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1546"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:867" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Linux Kernel do_mremap Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985"/>
        <description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:44.503-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.21-4.0.2.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1550"/>
          <criterion comment="kernel-smp version is less than 2.4.21-4.0.2.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1549"/>
          <criterion comment="kernel-bigmem version is less than 2.4.21-4.0.2.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1548"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:866" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 CVS Server root Directory Access Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0977"/>
        <description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.684-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-14" negate="false" test_ref="oval:org.mitre.oval:tst:1551"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/ is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:1576"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8653" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the TCP Loopback/Fusion Code May Lead to a System Hang Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3469"/>
        <description>Unspecified vulnerability in the TCP Loopback/Fusion implementation in Sun Solaris 10 allows local users to cause a denial of service (resource exhaustion and service hang) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-03T10:36:57.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-03T16:51:06.782-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.600-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.390-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102963" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-10 or later installed" test_ref="oval:org.mitre.oval:tst:4665" negate="true"/>
          <criterion comment="Patch 118833-17 or later installed" test_ref="oval:org.mitre.oval:tst:4625" negate="false"/>
          <criterion comment="Patch 118833-36 or earlier installed" test_ref="oval:org.mitre.oval:tst:4778" negate="false"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102963" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-10 or later installed" test_ref="oval:org.mitre.oval:tst:4966" negate="true"/>
          <criterion comment="Patch 118855-15 or later installed" test_ref="oval:org.mitre.oval:tst:4714" negate="false"/>
          <criterion comment="Patch 118855-36 or earlier installed" test_ref="oval:org.mitre.oval:tst:4725" negate="false"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:865" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 kdepim VCF File Information Reader BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>KDE Personal Information Management (kdepim)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0988"/>
        <description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.566-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdepim version is less than 3.1.3-3.3" negate="false" test_ref="oval:org.mitre.oval:tst:1552"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/share/services/kfile_vcf.desktop is readable">
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1563"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1562"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1561"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:864" version="4" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Multiple stack-based BO Vulnerabilities in Apache</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.327-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.722-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.863-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:55:50.726-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:44.258-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.46-26.ent" negate="false" test_ref="oval:org.mitre.oval:tst:1553"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd.worker is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:863" version="4" class="vulnerability">
      <metadata>
        <title>Red Hat Multiple stack-based BO Vulnerabilities in Apache</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>httpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:37.702-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.502-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.863-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:55:50.619-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:43.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.9" negate="false" test_ref="oval:org.mitre.oval:tst:1554"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd.worker is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8622" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3868"/>
        <description>Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:08.423-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:46.751-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:30.452-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:26.391-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:03.855-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:34:22.317-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:39.446-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:44.767-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:41.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:862" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 sysstat port and trigger Scripts symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Sysstat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0107"/>
        <description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:21.223-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.313-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="sysstat version is less than 4.0.7-4.EL3.2" negate="false" test_ref="oval:org.mitre.oval:tst:1555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8613" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3800"/>
        <description>Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:42.352-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:45.633-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:29.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:861" version="4" class="vulnerability">
      <metadata>
        <title>rpc.mountd Denial of Service via NFS Mount</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>nfs-utils packages</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0154"/>
        <description>rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:26.329-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.061-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.992-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T21:00:14.572-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:43.548-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="nfs-utils version is less than 1.0.6-7.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1557"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpc.mountd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1556"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8608" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3876" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3876"/>
        <description>Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:13.780-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:43.979-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:28.530-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:17.924-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:03.398-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:34:01.048-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:39.241-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:34.078-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:40.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8603" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3874"/>
        <description>Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:12.227-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:42.619-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:27.102-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:18.065-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:03.199-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:34:01.529-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:39.031-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:34.258-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:40.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:860" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel do_mremap Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985"/>
        <description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:42.419-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.810-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1560"/>
          <criterion comment="kernel-smp version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1559"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:86" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 LBXProxy Display Name Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>lbxproxy</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0090"/>
        <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File lbxproxy exists" negate="false" test_ref="oval:org.mitre.oval:tst:2964"/>
          <criterion comment="Patch 108652-51 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2963"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File lbxproxy SGID and executable">
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2962"/>
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2961"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8599" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in GNU tar (see gtar(1)) May Lead to Files Being Overwritten, Execution of Arbitrary Code, or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4476"/>
        <description>Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-26T14:24:08.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:04.724-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:42.064-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:26.445-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 273551">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 118191-04 or later installed" test_ref="oval:org.mitre.oval:tst:21169"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273551">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139099-03 or later installed" test_ref="oval:org.mitre.oval:tst:20999"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 273551">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 118192-04 or later installed" test_ref="oval:org.mitre.oval:tst:21124"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273551">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139100-03 or later installed" test_ref="oval:org.mitre.oval:tst:21085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:859" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel Real Time Clock Data Leakage</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0984"/>
        <description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.989-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1560"/>
          <criterion comment="kernel-smp version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1559"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8584" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3981"/>
        <description>Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:48.302-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:50.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:51.460-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8584 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:21.857-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:50.063-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.16-4.el4" test_ref="oval:org.mitre.oval:tst:39002"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39838"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39032"/>
            <criterion comment="firefox is earlier than 0:3.0.16-1.el5_4" test_ref="oval:org.mitre.oval:tst:39721"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:858" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat kdepim VCF File Information Reader BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDE Personal Information Management (kdepim)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0988"/>
        <description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.520-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdepim version is less than 3.1-6" negate="false" test_ref="oval:org.mitre.oval:tst:1564"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/share/services/kfile_vcf.desktop is readable">
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1563"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1562"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1561"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:857" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal Malformed Q.931 Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Tethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1013"/>
        <description>The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.490-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1575"/>
            <criterion comment="ethereal-gnome version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1574"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1573"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1572"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1571"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1570"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1569"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1568"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/tethereal is executable">
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1567"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1566"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1565"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8566" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3869"/>
        <description>Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:09.178-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:40.132-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:24.692-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:07.782-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:02.819-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:32.948-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:38.855-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:21.191-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:40.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:856" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal Malformed SMB Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1012"/>
        <description>The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:49.899-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1575"/>
            <criterion comment="ethereal-gnome version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1574"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1573"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1572"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1571"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1570"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1569"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1568"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/tethereal is executable">
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1567"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1566"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1565"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8558" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2673"/>
        <description>The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:21.171-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:37.867-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:22.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:06.586-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:02.622-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:29.009-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:38.652-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:19.658-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:40.112-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:855" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat CVS Server root Directory Access Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>CVS server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0977"/>
        <description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.699-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-13" negate="false" test_ref="oval:org.mitre.oval:tst:1577"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/ is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:1576"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8540" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux Extras 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3109"/>
        <description>Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:20.969-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:50.407-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:51.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="redhat-release is version 5" test_ref="oval:org.mitre.oval:tst:33325"/>
        <criteria operator="OR">
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:36649"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37229"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37035"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37509"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37441"/>
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.7-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:37490"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:854" version="3" class="vulnerability">
      <metadata>
        <title>RHE3 tcpdump DoS via ISAKMP Packets II</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0057"/>
        <description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:44.116-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8535" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running OpenSSL, Remote Unauthorized Data Injection, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:03.859-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:34.867-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:19.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:09.321-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:02.439-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:38.117-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:38.444-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:23.598-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:39.904-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02482">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="openssl.OPENSSL-PVT version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:20966"/>
            <criterion comment="openssl.OPENSSL-RUN version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21305"/>
            <criterion comment="openssl.OPENSSL-CER version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:20418"/>
            <criterion comment="openssl.OPENSSL-CONF version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21054"/>
            <criterion comment="openssl.OPENSSL-DOC version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:20471"/>
            <criterion comment="openssl.OPENSSL-INC version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21309"/>
            <criterion comment="openssl.OPENSSL-LIB version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:20594"/>
            <criterion comment="openssl.OPENSSL-MAN version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21258"/>
            <criterion comment="openssl.OPENSSL-MIS version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21380"/>
            <criterion comment="openssl.OPENSSL-SRC version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21406"/>
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21371"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02482">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="openssl.OPENSSL-PVT version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21401"/>
            <criterion comment="openssl.OPENSSL-RUN version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21226"/>
            <criterion comment="openssl.OPENSSL-CER version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20912"/>
            <criterion comment="openssl.OPENSSL-CONF version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20516"/>
            <criterion comment="openssl.OPENSSL-DOC version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21017"/>
            <criterion comment="openssl.OPENSSL-INC version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20853"/>
            <criterion comment="openssl.OPENSSL-LIB version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21188"/>
            <criterion comment="openssl.OPENSSL-MAN version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20482"/>
            <criterion comment="openssl.OPENSSL-SRC version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21318"/>
            <criterion comment="openssl.OPENSSL-MIS version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20462"/>
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02482">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21348"/>
            <criterion comment="openssl.OPENSSL-RUN version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21238"/>
            <criterion comment="openssl.OPENSSL-CER version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:20944"/>
            <criterion comment="openssl.OPENSSL-CONF version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:20917"/>
            <criterion comment="openssl.OPENSSL-DOC version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21411"/>
            <criterion comment="openssl.OPENSSL-INC version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:20833"/>
            <criterion comment="openssl.OPENSSL-LIB version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21259"/>
            <criterion comment="openssl.OPENSSL-MAN version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21140"/>
            <criterion comment="openssl.OPENSSL-SRC version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21462"/>
            <criterion comment="openssl.OPENSSL-MIS version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21184"/>
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21348"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:853" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 tcpdump Denial of Service via print_attr_string Function</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055"/>
        <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.687-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.098-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8520" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625"/>
        <description>XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:18.123-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:33.262-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:17.719-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:13.191-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:02.245-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:50.456-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:38.250-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:29.075-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:39.637-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:852" version="2" class="vulnerability">
      <metadata>
        <title>RHE3 tcpdump DoS via ISAKMP Packets</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0989"/>
        <description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.952-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8512" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX Running sendmail, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2261"/>
        <description>Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:01:59.793-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:32.422-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:17.459-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:12.108-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:02.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21292"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:20788"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40388 is installed" test_ref="oval:org.mitre.oval:tst:20863"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21292"/>
          <criterion negate="true" comment="Patch PHNE_40393 is installed" test_ref="oval:org.mitre.oval:tst:21246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:851" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via ISAKMP Packets II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0057"/>
        <description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:40.838-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:850" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via print_attr_string Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055"/>
        <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:36.651-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8496" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer and Integer Overflow Vulnerabilities in Python (python(1)) May Lead to a Denial of Service (DoS) or Allow Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4965"/>
        <description>Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:09.112-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:17.823-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:29.099-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143506-01 or later installed" test_ref="oval:org.mitre.oval:tst:20998"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143507-01 or later installed" test_ref="oval:org.mitre.oval:tst:20927"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:849" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat sysstat port and trigger Scripts symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>sysstat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0107"/>
        <description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.135-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="sysstat version is less than 4.0.7-4.rhl9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1579"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8488" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "Status.pm" May Lead to Denial of Service (DoS) or Unauthorized Access to Data</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0796"/>
        <description>Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-16T15:16:58.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-17T22:26:12.371-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:31.276-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:16.198-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 272230">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 120543-15 or later installed" test_ref="oval:org.mitre.oval:tst:20986"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 272230">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 120544-15 or later installed" test_ref="oval:org.mitre.oval:tst:21020"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="Solaris 10 bundled Apache 2.0 web server service is enable" test_ref="oval:org.mitre.oval:tst:21122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8475" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3872" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3872"/>
        <description>Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:10.687-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:29.478-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:14.737-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:07.492-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:01.331-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:32.727-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:38.080-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:41.926-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:39.360-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:847" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via ISAKMP Packets</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0989"/>
        <description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:51.672-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.169-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:846" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat gdk-pixbuf Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>gdk-pixbuf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0111"/>
        <description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.497-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.959-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable configuration">
          <criterion comment="gdk-pixbuf version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1586"/>
          <criterion comment="gdk-pixbuf-devel version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1585"/>
          <criterion comment="gdk-pixbuf-gnome version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1584"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8453" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2676"/>
        <description>Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:23.448-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:27.161-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:12.965-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:11.013-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:00.907-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:42.813-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:37.882-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:25.712-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:39.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:845" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 gdk-pixbuf Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gdk-pixbuf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0111"/>
        <description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:44.319-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable configuration">
          <criterion comment="gdk-pixbuf version is less than 0.22.0-6.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:1589"/>
          <criterion comment="gdk-pixbuf-devel version is less than 0.22.0-6.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:1588"/>
          <criterion comment="gdk-pixbuf-gnome version is less than 0.22.0-6.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:1587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8445" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer and Integer Overflow Vulnerabilities in Python (python(1)) May Lead to a Denial of Service (DoS) or Allow Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2315" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2315"/>
        <description>Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules.  NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:10.453-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:16.977-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:26.143-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143506-01 or later installed" test_ref="oval:org.mitre.oval:tst:20998"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143507-01 or later installed" test_ref="oval:org.mitre.oval:tst:20927"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8444" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Solaris Trusted Extensions due to Missing Libraries may Allow Privilege Escalation</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0310"/>
        <description>Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software updates.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:09.783-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:16.767-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:25.851-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 275410">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 143502-01 or later installed" test_ref="oval:org.mitre.oval:tst:20864"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 275410">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 143503-01 or later installed" test_ref="oval:org.mitre.oval:tst:20393"/>
          </criteria>
        </criteria>
        <criterion comment="System is configured to use Solaris Trusted Extensions (labeld service is online)" test_ref="oval:org.mitre.oval:tst:11134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8415" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2675"/>
        <description>Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:22.665-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:23.644-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:09.779-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:04.730-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:00.428-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:24.214-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:37.693-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:17.175-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:38.814-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:840" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Request Smuggling</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:84" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.12 Vulnerability in OSI Dissector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0429" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0429"/>
        <description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.040-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8396" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3873" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3873"/>
        <description>The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:11.474-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:21.820-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:07.739-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:05.263-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:02:00.247-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:27.583-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:37.511-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:38.872-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:38.554-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:839" version="3" deprecated="true" class="vulnerability">
      <metadata>
        <title>mod_python Web Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mod_python</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0973" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0973"/>
        <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:59.304-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.430-04:00">ACCEPTED</status_change>
            <modified date="2007-05-08T07:29:32.570-04:00" comment="Deprecated becased this definition is a duplicate of oval:org.mitre.oval:def:828">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-08T07:29:32.570-04:00">DEPRECATED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.470-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_python version is less than 3.0.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:1612"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:838" version="3" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Mutt BO in Index Menu</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0078"/>
        <description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.067-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mutt version is less than 1.4.1-3.4" negate="false" test_ref="oval:org.mitre.oval:tst:1603"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mutt is executable">
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2637"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2636"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:837" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel do_mremap Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mremap</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077"/>
        <description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:54.124-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.044-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8366" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Unauthorized Data Injection, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:01.435-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:20.568-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:06.772-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:00.896-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:59.989-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:11.732-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:37.325-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:30.157-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:38.278-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02498">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21301"/>
          <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21187"/>
          <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21265"/>
          <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21212"/>
          <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20981"/>
          <criterion comment="hpuxwsAPCH32.APACHE version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20369"/>
          <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21323"/>
          <criterion comment="hpuxwsAPCH32.APACHE2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21018"/>
          <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21151"/>
          <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21352"/>
          <criterion comment="hpuxwsAPCH32.AUTH_LDAP version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20845"/>
          <criterion comment="hpuxwsAPCH32.AUTH_LDAP2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21339"/>
          <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21279"/>
          <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21139"/>
          <criterion comment="hpuxwsAPCH32.MOD_JK version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21210"/>
          <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20570"/>
          <criterion comment="hpuxwsAPCH32.MOD_JK2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21286"/>
          <criterion comment="hpuxwsAPCH32.WEBPROXY version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21252"/>
          <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21321"/>
          <criterion comment="hpuxwsAPCH32.MOD_PERL version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21268"/>
          <criterion comment="hpuxwsAPCH32.MOD_PERL2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20425"/>
          <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:836" version="2" class="vulnerability">
      <metadata>
        <title>Vicam USB Driver Data Copy Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Vicam USB driver</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0075"/>
        <description>The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:52.053-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.802-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8350" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3797"/>
        <description>Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.887-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:19.145-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:05.699-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:835" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel ncp_lookup Function BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010"/>
        <description>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:46.479-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8349" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "PerlRun.pm" May Lead to Denial of Service (DoS) or Unauthorized Access to Data</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1349"/>
        <description>PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-16T15:16:58.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-17T22:26:12.189-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:18.858-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:05.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 272230">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 120543-15 or later installed" test_ref="oval:org.mitre.oval:tst:20986"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 272230">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 120544-15 or later installed" test_ref="oval:org.mitre.oval:tst:21020"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="Solaris 10 bundled Apache 2.0 web server service is enable" test_ref="oval:org.mitre.oval:tst:21122"/>
          <criterion comment="PerlRun.pm component is used" test_ref="oval:org.mitre.oval:tst:21159"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:834" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel R128 DRI Limits Checking Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003"/>
        <description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:58.073-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8334" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in lbxproxy(1) may Allow Unauthorized Read Access to Files</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4070"/>
        <description>Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 20070725 allows local users to read arbitrary files with root group ownership via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-01T13:14:10.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-01T22:21:39.310-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.437-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 119067-08 or later installed" test_ref="oval:org.mitre.oval:tst:5089" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112785-62 or later installed" test_ref="oval:org.mitre.oval:tst:4378" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119059-28 or later installed" test_ref="oval:org.mitre.oval:tst:4559" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 119068-08 or later installed" test_ref="oval:org.mitre.oval:tst:4495" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 112786-51 or later installed" test_ref="oval:org.mitre.oval:tst:4915" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119060-27 or later installed" test_ref="oval:org.mitre.oval:tst:5067" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8330" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3877" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3877"/>
        <description>Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:14.552-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:17.683-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:04.365-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:08.516-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:59.658-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:35.811-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:37.109-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:22.128-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:37.844-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:833" version="2" deprecated="true" class="vulnerability">
      <metadata>
        <title>XMLSoft Libxml2 Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XMLSoft Libxml2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0110"/>
        <description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:47.353-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.231-04:00">ACCEPTED</status_change>
            <modified date="2007-05-08T07:29:32.570-04:00" comment="Deprecated becased this definition is a duplicate of oval:org.mitre.oval:def:875">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-08T07:29:32.570-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="libxml2 version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1609"/>
          <criterion comment="libxml2-devel version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1608"/>
          <criterion comment="libxml2-python version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1607"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:832" version="2" class="vulnerability">
      <metadata>
        <title>XFree86 Improper Handling of Font Files</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0106"/>
        <description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:53.814-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.024-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-55.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1610"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:831" version="2" class="vulnerability">
      <metadata>
        <title>XFree86 Buffer Overflow in CopyISOLatin1Lowered Function</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0084"/>
        <description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:54.698-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-55.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1610"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8305" version="10" class="vulnerability">
      <metadata>
        <title>HP Enterprise Cluster Master Toolkit (ECMT) running on HP-UX, Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4184"/>
        <description>Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.11.31 (11i v3) allows local users to gain access to an Oracle or Sybase database via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:01:58.090-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:17.102-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:03.661-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:02.829-05:00">INTERIM</status_change>
            <status_change date="2014-03-10T04:00:52.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:18.525-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:36.987-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:14.963-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:37.718-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02464">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SG-Oracle-Tool.CM-ORACLE is installed" test_ref="oval:org.mitre.oval:tst:21214"/>
            <criterion comment="SG-Sybase-Tool.CM-SYBASE is installed" test_ref="oval:org.mitre.oval:tst:20958"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_40230 is installed" test_ref="oval:org.mitre.oval:tst:20313"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02464">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SG-Oracle-Tool.CM-ORACLE is installed" test_ref="oval:org.mitre.oval:tst:21214"/>
            <criterion comment="SG-Sybase-Tool.CM-SYBASE is installed" test_ref="oval:org.mitre.oval:tst:20958"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_40229 is installed" test_ref="oval:org.mitre.oval:tst:20702"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:830" version="2" class="vulnerability">
      <metadata>
        <title>XFree86 Buffer Overflow in dirfile</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083"/>
        <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.757-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.643-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-55.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1610"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8290" version="1" class="vulnerability">
      <metadata>
        <title>An Integer Overflow Vulnerability in GIMP(1) May Lead to Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1570" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1570"/>
        <description>Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:09.387-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:03.556-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:17.105-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274390">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143510-01 or later installed" test_ref="oval:org.mitre.oval:tst:20765"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274390">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143511-01 or later installed" test_ref="oval:org.mitre.oval:tst:20779"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8280" version="5" class="vulnerability">
      <metadata>
        <title>OpenOffice_org WMF buffer overflows</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux Professional 9.3</platform>
          <platform>SUSE Linux Desktop 1.0</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
          <product>OpenOffice_org1</product>
          <product>OpenOffice_org1-ar</product>
          <product>OpenOffice_org1-ca</product>
          <product>OpenOffice_org1-cs</product>
          <product>OpenOffice_org1-da</product>
          <product>OpenOffice_org1-de</product>
          <product>OpenOffice_org1-el</product>
          <product>OpenOffice_org1-en</product>
          <product>OpenOffice_org1-es</product>
          <product>OpenOffice_org1-et</product>
          <product>OpenOffice_org1-fi</product>
          <product>OpenOffice_org1-fr</product>
          <product>OpenOffice_org1-gnome</product>
          <product>OpenOffice_org1-hu</product>
          <product>OpenOffice_org1-it</product>
          <product>OpenOffice_org1-ja</product>
          <product>OpenOffice_org1-kde</product>
          <product>OpenOffice_org1-ko</product>
          <product>OpenOffice_org1-nl</product>
          <product>OpenOffice_org1-pl</product>
          <product>OpenOffice_org1-pt</product>
          <product>OpenOffice_org1-ru</product>
          <product>OpenOffice_org1-sk</product>
          <product>OpenOffice_org1-sl</product>
          <product>OpenOffice_org1-sv</product>
          <product>OpenOffice_org1-tr</product>
          <product>OpenOffice_org1-zh-CN</product>
          <product>OpenOffice_org1-zh-TW</product>
          <product>OpenOffice_org</product>
          <product>OpenOffice_org-af</product>
          <product>OpenOffice_org-be-BY</product>
          <product>OpenOffice_org-bg</product>
          <product>OpenOffice_org-ca</product>
          <product>OpenOffice_org-cs</product>
          <product>OpenOffice_org-cy</product>
          <product>OpenOffice_org-da</product>
          <product>OpenOffice_org-de</product>
          <product>OpenOffice_org-el</product>
          <product>OpenOffice_org-en</product>
          <product>OpenOffice_org-en-GB</product>
          <product>OpenOffice_org-es</product>
          <product>OpenOffice_org-et</product>
          <product>OpenOffice_org-fi</product>
          <product>OpenOffice_org-fr</product>
          <product>OpenOffice_org-galleries</product>
          <product>OpenOffice_org-gnome</product>
          <product>OpenOffice_org-gu-IN</product>
          <product>OpenOffice_org-hr</product>
          <product>OpenOffice_org-hu</product>
          <product>OpenOffice_org-hunspell</product>
          <product>OpenOffice_org-it</product>
          <product>OpenOffice_org-ja</product>
          <product>OpenOffice_org-kde</product>
          <product>OpenOffice_org-ko</product>
          <product>OpenOffice_org-mono</product>
          <product>OpenOffice_org-nb</product>
          <product>OpenOffice_org-nl</product>
          <product>OpenOffice_org-nn</product>
          <product>OpenOffice_org-officebean</product>
          <product>OpenOffice_org-pa-IN</product>
          <product>OpenOffice_org-pl</product>
          <product>OpenOffice_org-pt</product>
          <product>OpenOffice_org-pt-BR</product>
          <product>OpenOffice_org-ru</product>
          <product>OpenOffice_org-sk</product>
          <product>OpenOffice_org-sl</product>
          <product>OpenOffice_org-sv</product>
          <product>OpenOffice_org-tr</product>
          <product>OpenOffice_org-vi</product>
          <product>OpenOffice_org-xh</product>
          <product>OpenOffice_org-zh-CN</product>
          <product>OpenOffice_org-zh-TW</product>
          <product>OpenOffice_org-zu</product>
        </affected>
        <reference ref_id="CVE-2006-5870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5870" source="CVE"/>
        <description>Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-22T11:38:47">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:07.872-04:00">DRAFT</status_change>
            <modified comment="Assigned new id to ste used for tst:4278." date="2007-08-02T14:42:00.077-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-08-20T08:04:41.466-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.864-04:00">ACCEPTED</status_change>
            <modified comment="Added a datatype of 'version' of the release and version entities for several rpminfo_states." date="2010-09-02T21:15:00.227-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T21:18:40.737-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:39.430-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8280 - Typo Corrections" date="2014-05-22T11:03:00.270-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:06:07.371-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:48.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/novell:linux_desktop:9</cpe>
            <cpe>cpe:/novell:suse_linux:10.1</cpe>
            <cpe>cpe:/novell:suse_linux:10.0</cpe>
            <cpe>cpe:/novell:suse_linux:9.3:pro</cpe>
            <cpe>cpe:/novell:suse_linux:1.0:desktop</cpe>
            <cpe>cpe:/novell:suse_linux_enterprise:10:desktop</cpe>
            <cpe>cpe:/novell:OpenOffice_org1</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-ar</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-ca</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-cs</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-da</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-de</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-el</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-en</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-es</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-et</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-fi</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-fr</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-gnome</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-hu</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-it</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-ja</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-kde</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-ko</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-nl</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-pl</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-pt</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-ru</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-sk</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-sl</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-sv</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-tr</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-zh-CN</cpe>
            <cpe>cpe:/novell:OpenOffice_org1-zh-TW</cpe>
            <cpe>cpe:/novell:OpenOffice_org</cpe>
            <cpe>cpe:/novell:OpenOffice_org-af</cpe>
            <cpe>cpe:/novell:OpenOffice_org-be-BY</cpe>
            <cpe>cpe:/novell:OpenOffice_org-bg</cpe>
            <cpe>cpe:/novell:OpenOffice_org-ca</cpe>
            <cpe>cpe:/novell:OpenOffice_org-cs</cpe>
            <cpe>cpe:/novell:OpenOffice_org-cy</cpe>
            <cpe>cpe:/novell:OpenOffice_org-da</cpe>
            <cpe>cpe:/novell:OpenOffice_org-de</cpe>
            <cpe>cpe:/novell:OpenOffice_org-el</cpe>
            <cpe>cpe:/novell:OpenOffice_org-en</cpe>
            <cpe>cpe:/novell:OpenOffice_org-en-GB</cpe>
            <cpe>cpe:/novell:OpenOffice_org-es</cpe>
            <cpe>cpe:/novell:OpenOffice_org-et</cpe>
            <cpe>cpe:/novell:OpenOffice_org-fi</cpe>
            <cpe>cpe:/novell:OpenOffice_org-fr</cpe>
            <cpe>cpe:/novell:OpenOffice_org-galleries</cpe>
            <cpe>cpe:/novell:OpenOffice_org-gnome</cpe>
            <cpe>cpe:/novell:OpenOffice_org-gu-IN</cpe>
            <cpe>cpe:/novell:OpenOffice_org-hr</cpe>
            <cpe>cpe:/novell:OpenOffice_org-hu</cpe>
            <cpe>cpe:/novell:OpenOffice_org-hunspell</cpe>
            <cpe>cpe:/novell:OpenOffice_org-it</cpe>
            <cpe>cpe:/novell:OpenOffice_org-ja</cpe>
            <cpe>cpe:/novell:OpenOffice_org-kde</cpe>
            <cpe>cpe:/novell:OpenOffice_org-ko</cpe>
            <cpe>cpe:/novell:OpenOffice_org-mono</cpe>
            <cpe>cpe:/novell:OpenOffice_org-nb</cpe>
            <cpe>cpe:/novell:OpenOffice_org-nl</cpe>
            <cpe>cpe:/novell:OpenOffice_org-nn</cpe>
            <cpe>cpe:/novell:OpenOffice_org-officebean</cpe>
            <cpe>cpe:/novell:OpenOffice_org-pa-IN</cpe>
            <cpe>cpe:/novell:OpenOffice_org-pl</cpe>
            <cpe>cpe:/novell:OpenOffice_org-pt</cpe>
            <cpe>cpe:/novell:OpenOffice_org-pt-BR</cpe>
            <cpe>cpe:/novell:OpenOffice_org-ru</cpe>
            <cpe>cpe:/novell:OpenOffice_org-sk</cpe>
            <cpe>cpe:/novell:OpenOffice_org-sl</cpe>
            <cpe>cpe:/novell:OpenOffice_org-sv</cpe>
            <cpe>cpe:/novell:OpenOffice_org-tr</cpe>
            <cpe>cpe:/novell:OpenOffice_org-vi</cpe>
            <cpe>cpe:/novell:OpenOffice_org-xh</cpe>
            <cpe>cpe:/novell:OpenOffice_org-zh-CN</cpe>
            <cpe>cpe:/novell:OpenOffice_org-zh-TW</cpe>
            <cpe>cpe:/novell:OpenOffice_org-zu</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exploitable Novell Linux Desktop 9 or SUSE Linux Desktop 1.0 Vulnerability Exists">
          <criteria operator="AND" comment="Potential System Vulnerability Exists">
            <criteria operator="OR" comment="Potential Novell Linux Desktop 9 or SUSE Linux Desktop 1.0 Vulnerability Exists">
              <extend_definition comment="Novell Linux Desktop 9 is installed" definition_ref="oval:org.mitre.oval:def:2090"/>
              <extend_definition comment="SUSE Linux Desktop 1.0 is installed" definition_ref="oval:org.mitre.oval:def:1366"/>
            </criteria>
            <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3152"/>
          </criteria>
          <criteria operator="OR" comment="Potential Package Vulnerability Exists">
            <criterion comment="OpenOffice_org is installed" test_ref="oval:org.mitre.oval:tst:4677"/>
            <criterion comment="OpenOffice_org-ar is installed" test_ref="oval:org.mitre.oval:tst:4205"/>
            <criterion comment="OpenOffice_org-ca is installed" test_ref="oval:org.mitre.oval:tst:4866"/>
            <criterion comment="OpenOffice_org-cs is installed" test_ref="oval:org.mitre.oval:tst:4348"/>
            <criterion comment="OpenOffice_org-da is installed" test_ref="oval:org.mitre.oval:tst:4791"/>
            <criterion comment="OpenOffice_org-de is installed" test_ref="oval:org.mitre.oval:tst:5008"/>
            <criterion comment="OpenOffice_org-el is installed" test_ref="oval:org.mitre.oval:tst:4238"/>
            <criterion comment="OpenOffice_org-en is installed" test_ref="oval:org.mitre.oval:tst:4287"/>
            <criterion comment="OpenOffice_org-es is installed" test_ref="oval:org.mitre.oval:tst:4751"/>
            <criterion comment="OpenOffice_org-et is installed" test_ref="oval:org.mitre.oval:tst:5033"/>
            <criterion comment="OpenOffice_org-fi is installed" test_ref="oval:org.mitre.oval:tst:4254"/>
            <criterion comment="OpenOffice_org-fr is installed" test_ref="oval:org.mitre.oval:tst:4518"/>
            <criterion comment="OpenOffice_org-gnome is installed" test_ref="oval:org.mitre.oval:tst:4675"/>
            <criterion comment="OpenOffice_org-hu is installed" test_ref="oval:org.mitre.oval:tst:4235"/>
            <criterion comment="OpenOffice_org-it is installed" test_ref="oval:org.mitre.oval:tst:4849"/>
            <criterion comment="OpenOffice_org-ja is installed" test_ref="oval:org.mitre.oval:tst:4671"/>
            <criterion comment="OpenOffice_org-kde is installed" test_ref="oval:org.mitre.oval:tst:4544"/>
            <criterion comment="OpenOffice_org-ko is installed" test_ref="oval:org.mitre.oval:tst:4941"/>
            <criterion comment="OpenOffice_org-nl is installed" test_ref="oval:org.mitre.oval:tst:4956"/>
            <criterion comment="OpenOffice_org-pl is installed" test_ref="oval:org.mitre.oval:tst:4556"/>
            <criterion comment="OpenOffice_org-pt is installed" test_ref="oval:org.mitre.oval:tst:4724"/>
            <criterion comment="OpenOffice_org-pt-BR is installed" test_ref="oval:org.mitre.oval:tst:4754"/>
            <criterion comment="OpenOffice_org-ru is installed" test_ref="oval:org.mitre.oval:tst:4980"/>
            <criterion comment="OpenOffice_org-sk is installed" test_ref="oval:org.mitre.oval:tst:4739"/>
            <criterion comment="OpenOffice_org-sl is installed" test_ref="oval:org.mitre.oval:tst:4596"/>
            <criterion comment="OpenOffice_org-sv is installed" test_ref="oval:org.mitre.oval:tst:4550"/>
            <criterion comment="OpenOffice_org-tr is installed" test_ref="oval:org.mitre.oval:tst:4210"/>
            <criterion comment="OpenOffice_org-zh-CN is installed" test_ref="oval:org.mitre.oval:tst:4875"/>
            <criterion comment="OpenOffice_org-zh-TW is installed" test_ref="oval:org.mitre.oval:tst:4555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Exploitable SUSE Linux 10.1 Vulnerability Exists">
          <criteria operator="AND" comment="Potential System Vulnerability Exists">
            <extend_definition comment="SUSE Linux 10.1 is installed" definition_ref="oval:org.mitre.oval:def:2157"/>
            <criteria operator="OR" comment="Potential Architecture Vulnerability Exists">
              <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3152"/>
              <criterion comment="ppc architecture" test_ref="oval:org.mitre.oval:tst:4278"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Potential Package Vulnerability Exists">
            <criteria operator="AND" comment="Potential Package OpenOffice_org Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org is installed" definition_ref="oval:org.mitre.oval:def:8865"/>
              <criterion comment="Package OpenOffice_org version-release is less than 2.0.2-27.15" test_ref="oval:org.mitre.oval:tst:4673"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-gnome Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-gnome is installed" definition_ref="oval:org.mitre.oval:def:8914"/>
              <criterion comment="Package OpenOffice_org-gnome version-release is less than 2.0.2-27.15" test_ref="oval:org.mitre.oval:tst:4905"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-kde Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-kde is installed" definition_ref="oval:org.mitre.oval:def:9199"/>
              <criterion comment="Package OpenOffice_org-kde version-release is less than 2.0.2-27.15" test_ref="oval:org.mitre.oval:tst:4272"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-mono Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-mono is installed" definition_ref="oval:org.mitre.oval:def:8222"/>
              <criterion comment="Package OpenOffice_org-mono version-release is less than 2.0.2-27.15" test_ref="oval:org.mitre.oval:tst:4421"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-officebean Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-officebean is installed" definition_ref="oval:org.mitre.oval:def:8541"/>
              <criterion comment="Package OpenOffice_org-officebean version-release is less than 2.0.2-27.15" test_ref="oval:org.mitre.oval:tst:5087"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Exploitable SUSE Linux 10.0 Vulnerability Exists">
          <criteria operator="AND" comment="Potential System Vulnerability Exists">
            <extend_definition comment="SUSE Linux 10.0 is installed" definition_ref="oval:org.mitre.oval:def:2027"/>
            <criteria operator="OR" comment="Potential Architecture Vulnerability Exists">
              <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3152"/>
              <criterion comment="ppc architecture" test_ref="oval:org.mitre.oval:tst:4278"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Potential Package Vulnerability Exists">
            <criteria operator="AND" comment="Potential Package OpenOffice_org Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org is installed" definition_ref="oval:org.mitre.oval:def:8865"/>
              <criterion comment="Package OpenOffice_org version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4770"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-af Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-af is installed" definition_ref="oval:org.mitre.oval:def:8974"/>
              <criterion comment="Package OpenOffice_org-af version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5076"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-ar Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-ar is installed" definition_ref="oval:org.mitre.oval:def:8663"/>
              <criterion comment="Package OpenOffice_org-ar version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4524"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-be-BY Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-be-BY is installed" definition_ref="oval:org.mitre.oval:def:8432"/>
              <criterion comment="Package OpenOffice_org-be-BY version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4761"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-bg Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-bg is installed" definition_ref="oval:org.mitre.oval:def:8403"/>
              <criterion comment="Package OpenOffice_org-bg version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4224"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-ca Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-ca is installed" definition_ref="oval:org.mitre.oval:def:8887"/>
              <criterion comment="Package OpenOffice_org-ca version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4449"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-cs Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-cs is installed" definition_ref="oval:org.mitre.oval:def:8733"/>
              <criterion comment="Package OpenOffice_org-cs version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4479"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-cy Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-cy is installed" definition_ref="oval:org.mitre.oval:def:8329"/>
              <criterion comment="Package OpenOffice_org-cy version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4986"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-da Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-da is installed" definition_ref="oval:org.mitre.oval:def:8998"/>
              <criterion comment="Package OpenOffice_org-da version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4833"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-de Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-de is installed" definition_ref="oval:org.mitre.oval:def:8688"/>
              <criterion comment="Package OpenOffice_org-de version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4410"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-el Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-el is installed" definition_ref="oval:org.mitre.oval:def:8801"/>
              <criterion comment="Package OpenOffice_org-el version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4561"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-en-GB Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-en-GB is installed" definition_ref="oval:org.mitre.oval:def:8829"/>
              <criterion comment="Package OpenOffice_org-en-GB version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4226"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-es Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-es is installed" definition_ref="oval:org.mitre.oval:def:8583"/>
              <criterion comment="Package OpenOffice_org-es version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4656"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-et Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-et is installed" definition_ref="oval:org.mitre.oval:def:8678"/>
              <criterion comment="Package OpenOffice_org-et version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5031"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-fi Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-fi is installed" definition_ref="oval:org.mitre.oval:def:8451"/>
              <criterion comment="Package OpenOffice_org-fi version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4716"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-fr Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-fr is installed" definition_ref="oval:org.mitre.oval:def:8215"/>
              <criterion comment="Package OpenOffice_org-fr version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5020"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-galleries Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-galleries is installed" definition_ref="oval:org.mitre.oval:def:8997"/>
              <criterion comment="Package OpenOffice_org-galleries version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4981"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-gnome Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-gnome is installed" definition_ref="oval:org.mitre.oval:def:8914"/>
              <criterion comment="Package OpenOffice_org-gnome version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5098"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-gu-IN Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-gu-IN is installed" definition_ref="oval:org.mitre.oval:def:8341"/>
              <criterion comment="Package OpenOffice_org-gu-IN version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4763"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-hr Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-hr is installed" definition_ref="oval:org.mitre.oval:def:8715"/>
              <criterion comment="Package OpenOffice_org-hr version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4280"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-hu Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-hu is installed" definition_ref="oval:org.mitre.oval:def:8228"/>
              <criterion comment="Package OpenOffice_org-hu version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5191"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-hunspell Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-hunspell is installed" definition_ref="oval:org.mitre.oval:def:8892"/>
              <criterion comment="Package OpenOffice_org-hunspell version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5152"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-it Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-it is installed" definition_ref="oval:org.mitre.oval:def:9104"/>
              <criterion comment="Package OpenOffice_org-it version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4644"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-ja Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-ja is installed" definition_ref="oval:org.mitre.oval:def:8987"/>
              <criterion comment="Package OpenOffice_org-ja version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4620"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-kde Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-kde is installed" definition_ref="oval:org.mitre.oval:def:9199"/>
              <criterion comment="Package OpenOffice_org-kde version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4921"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-ko Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-ko is installed" definition_ref="oval:org.mitre.oval:def:8352"/>
              <criterion comment="Package OpenOffice_org-ko version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5038"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-mono Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-mono is installed" definition_ref="oval:org.mitre.oval:def:8222"/>
              <criterion comment="Package OpenOffice_org-mono version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5103"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-nb Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-nb is installed" definition_ref="oval:org.mitre.oval:def:8804"/>
              <criterion comment="Package OpenOffice_org-nb version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5128"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-nl Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-nl is installed" definition_ref="oval:org.mitre.oval:def:8611"/>
              <criterion comment="Package OpenOffice_org-nl version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4520"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-nn Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-nn is installed" definition_ref="oval:org.mitre.oval:def:8501"/>
              <criterion comment="Package OpenOffice_org-nn version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4274"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-officebean Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-officebean is installed" definition_ref="oval:org.mitre.oval:def:8541"/>
              <criterion comment="Package OpenOffice_org-officebean version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4420"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-pa-IN Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-pa-IN is installed" definition_ref="oval:org.mitre.oval:def:8882"/>
              <criterion comment="Package OpenOffice_org-pa-IN version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4209"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-pl Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-pl is installed" definition_ref="oval:org.mitre.oval:def:8799"/>
              <criterion comment="Package OpenOffice_org-pl version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4456"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-pt Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-pt is installed" definition_ref="oval:org.mitre.oval:def:8664"/>
              <criterion comment="Package OpenOffice_org-pt version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4940"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-pt-BR Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-pt-BR is installed" definition_ref="oval:org.mitre.oval:def:8886"/>
              <criterion comment="Package OpenOffice_org-pt-BR version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5180"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-ru Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-ru is installed" definition_ref="oval:org.mitre.oval:def:8389"/>
              <criterion comment="Package OpenOffice_org-ru version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5096"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-sk Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-sk is installed" definition_ref="oval:org.mitre.oval:def:8244"/>
              <criterion comment="Package OpenOffice_org-sk version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5058"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-sl Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-sl is installed" definition_ref="oval:org.mitre.oval:def:9181"/>
              <criterion comment="Package OpenOffice_org-sl version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4908"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-sv Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-sv is installed" definition_ref="oval:org.mitre.oval:def:8860"/>
              <criterion comment="Package OpenOffice_org-sv version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:5051"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-tr Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-tr is installed" definition_ref="oval:org.mitre.oval:def:8707"/>
              <criterion comment="Package OpenOffice_org-tr version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4258"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-vi Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-vi is installed" definition_ref="oval:org.mitre.oval:def:8288"/>
              <criterion comment="Package OpenOffice_org-vi version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4828"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-xh Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-xh is installed" definition_ref="oval:org.mitre.oval:def:8477"/>
              <criterion comment="Package OpenOffice_org-xh version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4893"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-zh-CN Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-zh-CN is installed" definition_ref="oval:org.mitre.oval:def:8995"/>
              <criterion comment="Package OpenOffice_org-zh-CN version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4331"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-zh-TW Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-zh-TW is installed" definition_ref="oval:org.mitre.oval:def:9146"/>
              <criterion comment="Package OpenOffice_org-zh-TW version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4204"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org-zu Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org-zu is installed" definition_ref="oval:org.mitre.oval:def:8269"/>
              <criterion comment="Package OpenOffice_org-zu version-release is less than 2.0.0-1.6" test_ref="oval:org.mitre.oval:tst:4850"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Exploitable SUSE Linux Professional 9.3 Vulnerability Exists">
          <criteria operator="AND" comment="Potential System Vulnerability Exists">
            <extend_definition comment="SUSE Linux Professional 9.3 is installed" definition_ref="oval:org.mitre.oval:def:2044"/>
            <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3152"/>
          </criteria>
          <criteria operator="OR" comment="Potential Package Vulnerability Exists">
            <criteria operator="AND" comment="Potential Package OpenOffice_org1 Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1 is installed" definition_ref="oval:org.mitre.oval:def:8264"/>
              <criterion comment="Package OpenOffice_org1 version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4622"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-ar Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-ar is installed" definition_ref="oval:org.mitre.oval:def:8777"/>
              <criterion comment="Package OpenOffice_org1-ar version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4923"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-ca Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-ca is installed" definition_ref="oval:org.mitre.oval:def:8915"/>
              <criterion comment="Package OpenOffice_org1-ca version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:5069"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-cs Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-cs is installed" definition_ref="oval:org.mitre.oval:def:8357"/>
              <criterion comment="Package OpenOffice_org1-cs version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4463"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-da Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-da is installed" definition_ref="oval:org.mitre.oval:def:8308"/>
              <criterion comment="Package OpenOffice_org1-da version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:5139"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-de Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-de is installed" definition_ref="oval:org.mitre.oval:def:8533"/>
              <criterion comment="Package OpenOffice_org1-de version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4368"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-el Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-el is installed" definition_ref="oval:org.mitre.oval:def:8652"/>
              <criterion comment="Package OpenOffice_org1-el version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4650"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-en Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-en is installed" definition_ref="oval:org.mitre.oval:def:8958"/>
              <criterion comment="Package OpenOffice_org1-en version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4537"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-es Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-es is installed" definition_ref="oval:org.mitre.oval:def:8705"/>
              <criterion comment="Package OpenOffice_org1-es version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4937"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-et Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-et is installed" definition_ref="oval:org.mitre.oval:def:8681"/>
              <criterion comment="Package OpenOffice_org1-et version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4627"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-fi Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-fi is installed" definition_ref="oval:org.mitre.oval:def:8815"/>
              <criterion comment="Package OpenOffice_org1-fi version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4462"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-fr Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-fr is installed" definition_ref="oval:org.mitre.oval:def:8672"/>
              <criterion comment="Package OpenOffice_org1-fr version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4404"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-gnome Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-gnome is installed" definition_ref="oval:org.mitre.oval:def:8342"/>
              <criterion comment="Package OpenOffice_org1-gnome version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4713"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-hu Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-hu is installed" definition_ref="oval:org.mitre.oval:def:8380"/>
              <criterion comment="Package OpenOffice_org1-hu version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:5127"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-it Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-it is installed" definition_ref="oval:org.mitre.oval:def:8691"/>
              <criterion comment="Package OpenOffice_org1-it version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4541"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-ja Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-ja is installed" definition_ref="oval:org.mitre.oval:def:9174"/>
              <criterion comment="Package OpenOffice_org1-ja version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4727"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-kde Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-kde is installed" definition_ref="oval:org.mitre.oval:def:8774"/>
              <criterion comment="Package OpenOffice_org1-kde version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4594"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-ko Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-ko is installed" definition_ref="oval:org.mitre.oval:def:9070"/>
              <criterion comment="Package OpenOffice_org1-ko version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4816"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-nl Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-nl is installed" definition_ref="oval:org.mitre.oval:def:9192"/>
              <criterion comment="Package OpenOffice_org1-nl version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4590"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-pl Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-pl is installed" definition_ref="oval:org.mitre.oval:def:8502"/>
              <criterion comment="Package OpenOffice_org1-pl version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:5010"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-pt Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-pt is installed" definition_ref="oval:org.mitre.oval:def:8906"/>
              <criterion comment="Package OpenOffice_org1-pt version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:5028"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-ru Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-ru is installed" definition_ref="oval:org.mitre.oval:def:9169"/>
              <criterion comment="Package OpenOffice_org1-ru version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4728"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-sk Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-sk is installed" definition_ref="oval:org.mitre.oval:def:8903"/>
              <criterion comment="Package OpenOffice_org1-sk version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:5118"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-sl Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-sl is installed" definition_ref="oval:org.mitre.oval:def:8773"/>
              <criterion comment="Package OpenOffice_org1-sl version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4598"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-sv Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-sv is installed" definition_ref="oval:org.mitre.oval:def:9168"/>
              <criterion comment="Package OpenOffice_org1-sv version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4806"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-tr Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-tr is installed" definition_ref="oval:org.mitre.oval:def:8310"/>
              <criterion comment="Package OpenOffice_org1-tr version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4775"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-zh-CN Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-zh-CN is installed" definition_ref="oval:org.mitre.oval:def:8604"/>
              <criterion comment="Package OpenOffice_org1-zh-CN version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:5086"/>
            </criteria>
            <criteria operator="AND" comment="Potential Package OpenOffice_org1-zh-TW Vulnerability Exists">
              <extend_definition comment="Package OpenOffice_org1-zh-TW is installed" definition_ref="oval:org.mitre.oval:def:8999"/>
              <criterion comment="Package OpenOffice_org1-zh-TW version-release is less than 1.1.3-4.7" test_ref="oval:org.mitre.oval:tst:4376"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Exploitable SUSE Linux Enterprise Desktop 10 Vulnerability Exists">
          <criteria operator="AND" comment="Potential System Vulnerability Exists">
            <extend_definition comment="SUSE Linux Enterprise Desktop 10 is installed" definition_ref="oval:org.mitre.oval:def:2106"/>
            <criteria operator="OR" comment="Potential Architecture Vulnerability Exists">
              <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3152"/>
              <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:1547"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Potential Package Vulnerability Exists">
            <criterion comment="OpenOffice_org is installed" test_ref="oval:org.mitre.oval:tst:4677"/>
            <criterion comment="OpenOffice_org-gnome is installed" test_ref="oval:org.mitre.oval:tst:4675"/>
            <criterion comment="OpenOffice_org-kde is installed" test_ref="oval:org.mitre.oval:tst:4544"/>
            <criterion comment="OpenOffice_org-mono is installed" test_ref="oval:org.mitre.oval:tst:4809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9199" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-kde is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:OpenOffice_org-kde"/>
        <description>Package OpenOffice_org-kde is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:11">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.674-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.395-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.790-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-kde is installed" test_ref="oval:org.mitre.oval:tst:4544"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9192" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-nl is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-nl"/>
        <description>Package OpenOffice_org1-nl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.778-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.343-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.725-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-nl is installed" test_ref="oval:org.mitre.oval:tst:4451"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9181" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-sl is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-sl"/>
        <description>Package OpenOffice_org-sl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:42">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.411-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.286-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-sl is installed" test_ref="oval:org.mitre.oval:tst:4596"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9174" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ja is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ja"/>
        <description>Package OpenOffice_org1-ja is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.648-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.230-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.540-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ja is installed" test_ref="oval:org.mitre.oval:tst:4794"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9169" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ru is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ru"/>
        <description>Package OpenOffice_org1-ru is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.904-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.177-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.477-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ru is installed" test_ref="oval:org.mitre.oval:tst:4542"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9168" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-sv is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-sv"/>
        <description>Package OpenOffice_org1-sv is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.040-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.125-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.418-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-sv is installed" test_ref="oval:org.mitre.oval:tst:4290"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9146" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-zh-TW is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-zh-TW"/>
        <description>Package OpenOffice_org-zh-TW is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:38">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.764-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.980-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-zh-TW is installed" test_ref="oval:org.mitre.oval:tst:4555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9104" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-it is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-it"/>
        <description>Package OpenOffice_org-it is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:04">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.574-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.918-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-it is installed" test_ref="oval:org.mitre.oval:tst:4849"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9070" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ko is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ko"/>
        <description>Package OpenOffice_org1-ko is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.732-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.863-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ko is installed" test_ref="oval:org.mitre.oval:tst:4418"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8999" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-zh-TW is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-zh-TW"/>
        <description>Package OpenOffice_org1-zh-TW is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.171-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.743-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.974-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-zh-TW is installed" test_ref="oval:org.mitre.oval:tst:4477"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8998" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-da is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-da"/>
        <description>Package OpenOffice_org-da is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:47">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.780-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.683-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.904-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-da is installed" test_ref="oval:org.mitre.oval:tst:4791"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8997" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-galleries is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-galleries"/>
        <description>Package OpenOffice_org-galleries is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:33">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.255-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.625-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-galleries is installed" test_ref="oval:org.mitre.oval:tst:4799"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8995" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-zh-CN is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-zh-CN"/>
        <description>Package OpenOffice_org-zh-CN is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:33">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.712-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.565-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-zh-CN is installed" test_ref="oval:org.mitre.oval:tst:4875"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8987" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ja is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ja"/>
        <description>Package OpenOffice_org-ja is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:07">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.622-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.500-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.635-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ja is installed" test_ref="oval:org.mitre.oval:tst:4671"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8974" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-af is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-af"/>
        <description>Package OpenOffice_org-af is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:15">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.334-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.440-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.570-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-af is installed" test_ref="oval:org.mitre.oval:tst:4549"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8958" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-en is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-en"/>
        <description>Package OpenOffice_org1-en is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.195-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.381-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-en is installed" test_ref="oval:org.mitre.oval:tst:4947"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8915" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ca is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ca"/>
        <description>Package OpenOffice_org1-ca is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:02.928-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.325-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.444-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ca is installed" test_ref="oval:org.mitre.oval:tst:4574"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8914" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-gnome is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-gnome"/>
        <description>Package OpenOffice_org-gnome is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:37">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.305-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.260-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.371-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-gnome is installed" test_ref="oval:org.mitre.oval:tst:4675"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8906" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-pt is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-pt"/>
        <description>Package OpenOffice_org1-pt is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.866-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.205-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.313-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-pt is installed" test_ref="oval:org.mitre.oval:tst:5167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8903" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-sk is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-sk"/>
        <description>Package OpenOffice_org1-sk is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.950-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.152-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-sk is installed" test_ref="oval:org.mitre.oval:tst:4843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8892" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-hunspell is installed</title>
        <affected family="unix">
          <platform>SUSE Linux 10.0</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-hunspell"/>
        <description>Package OpenOffice_org-hunspell is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:56">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.529-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.099-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-hunspell is installed" test_ref="oval:org.mitre.oval:tst:4443"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8887" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ca is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ca"/>
        <description>Package OpenOffice_org-ca is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:33">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.567-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.040-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ca is installed" test_ref="oval:org.mitre.oval:tst:4866"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8886" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-pt-BR is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-pt-BR"/>
        <description>Package OpenOffice_org-pt-BR is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:07">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.237-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.971-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.067-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-pt-BR is installed" test_ref="oval:org.mitre.oval:tst:4754"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8882" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-pa-IN is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-pa-IN"/>
        <description>Package OpenOffice_org-pa-IN is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:54">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.083-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.910-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.002-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-pa-IN is installed" test_ref="oval:org.mitre.oval:tst:4615"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8865" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org"/>
        <description>Package OpenOffice_org is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:09">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.247-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.849-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.936-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org is installed" test_ref="oval:org.mitre.oval:tst:4677"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8860" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-sv is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-sv"/>
        <description>Package OpenOffice_org-sv is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:53">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.506-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.789-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-sv is installed" test_ref="oval:org.mitre.oval:tst:4550"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8829" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-en-GB is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-en-GB"/>
        <description>Package OpenOffice_org-en-GB is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:11">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.980-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.732-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.798-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-en-GB is installed" test_ref="oval:org.mitre.oval:tst:4815"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8815" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-fi is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-fi"/>
        <description>Package OpenOffice_org1-fi is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.353-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.680-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-fi is installed" test_ref="oval:org.mitre.oval:tst:5169"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8804" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-nb is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-nb"/>
        <description>Package OpenOffice_org-nb is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:39">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.901-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.619-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-nb is installed" test_ref="oval:org.mitre.oval:tst:5021"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8801" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-el is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-el"/>
        <description>Package OpenOffice_org-el is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:07">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.924-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.553-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.610-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-el is installed" test_ref="oval:org.mitre.oval:tst:4238"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8799" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-pl is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-pl"/>
        <description>Package OpenOffice_org-pl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:59">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.128-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.489-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.533-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-pl is installed" test_ref="oval:org.mitre.oval:tst:4556"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8777" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ar is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ar"/>
        <description>Package OpenOffice_org1-ar is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:02.882-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.436-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.454-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ar is installed" test_ref="oval:org.mitre.oval:tst:4273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8774" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-kde is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-kde"/>
        <description>Package OpenOffice_org1-kde is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.694-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.383-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-kde is installed" test_ref="oval:org.mitre.oval:tst:4748"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8773" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-sl is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-sl"/>
        <description>Package OpenOffice_org1-sl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.994-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.330-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-sl is installed" test_ref="oval:org.mitre.oval:tst:5084"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8733" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-cs is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-cs"/>
        <description>Package OpenOffice_org-cs is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:39">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.637-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.268-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.259-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-cs is installed" test_ref="oval:org.mitre.oval:tst:4348"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8715" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-hr is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-hr"/>
        <description>Package OpenOffice_org-hr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:49">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.414-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.205-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-hr is installed" test_ref="oval:org.mitre.oval:tst:5026"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8707" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-tr is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-tr"/>
        <description>Package OpenOffice_org-tr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:15">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.558-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.146-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-tr is installed" test_ref="oval:org.mitre.oval:tst:4210"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8705" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-es is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-es"/>
        <description>Package OpenOffice_org1-es is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.244-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.092-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.017-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-es is installed" test_ref="oval:org.mitre.oval:tst:4329"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8691" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-it is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-it"/>
        <description>Package OpenOffice_org1-it is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.599-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.037-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.952-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-it is installed" test_ref="oval:org.mitre.oval:tst:4212"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8688" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-de is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-de"/>
        <description>Package OpenOffice_org-de is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:51">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.859-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.969-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-de is installed" test_ref="oval:org.mitre.oval:tst:5008"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8681" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-et is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-et"/>
        <description>Package OpenOffice_org1-et is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.304-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.915-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.818-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-et is installed" test_ref="oval:org.mitre.oval:tst:5094"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8678" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-et is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-et"/>
        <description>Package OpenOffice_org-et is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.091-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.853-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.752-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-et is installed" test_ref="oval:org.mitre.oval:tst:5033"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8672" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-fr is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-fr"/>
        <description>Package OpenOffice_org1-fr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.406-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.798-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.693-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-fr is installed" test_ref="oval:org.mitre.oval:tst:5105"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8664" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-pt is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-pt"/>
        <description>Package OpenOffice_org-pt is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:03">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.180-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.735-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.537-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-pt is installed" test_ref="oval:org.mitre.oval:tst:4724"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8663" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ar is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ar"/>
        <description>Package OpenOffice_org-ar is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.415-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.675-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.472-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ar is installed" test_ref="oval:org.mitre.oval:tst:4205"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8652" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-el is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-el"/>
        <description>Package OpenOffice_org1-el is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.150-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.535-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.317-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-el is installed" test_ref="oval:org.mitre.oval:tst:4345"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8611" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-nl is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-nl"/>
        <description>Package OpenOffice_org-nl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:42">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.942-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.477-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.251-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-nl is installed" test_ref="oval:org.mitre.oval:tst:4956"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8604" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-zh-CN is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-zh-CN"/>
        <description>Package OpenOffice_org1-zh-CN is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.127-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.426-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-zh-CN is installed" test_ref="oval:org.mitre.oval:tst:5187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8583" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-es is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-es"/>
        <description>Package OpenOffice_org-es is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:15">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.035-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.365-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-es is installed" test_ref="oval:org.mitre.oval:tst:4751"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8541" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-officebean is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-officebean"/>
        <description>Package OpenOffice_org-officebean is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:50">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.039-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.307-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-officebean is installed" test_ref="oval:org.mitre.oval:tst:5132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8533" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-de is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-de"/>
        <description>Package OpenOffice_org1-de is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.092-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.254-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.998-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-de is installed" test_ref="oval:org.mitre.oval:tst:4764"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8502" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-pl is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-pl"/>
        <description>Package OpenOffice_org1-pl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.818-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.200-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-pl is installed" test_ref="oval:org.mitre.oval:tst:4319"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8501" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-nn is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-nn"/>
        <description>Package OpenOffice_org-nn is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:46">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.988-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.144-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.856-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-nn is installed" test_ref="oval:org.mitre.oval:tst:4734"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8477" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-xh is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-xh"/>
        <description>Package OpenOffice_org-xh is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:29">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.658-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.087-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.791-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-xh is installed" test_ref="oval:org.mitre.oval:tst:4357"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8451" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-fi is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-fi"/>
        <description>Package OpenOffice_org-fi is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:22">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.142-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.025-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-fi is installed" test_ref="oval:org.mitre.oval:tst:4254"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8432" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-be-BY is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-be-BY"/>
        <description>Package OpenOffice_org-be-BY is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:25">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.465-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.964-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-be-BY is installed" test_ref="oval:org.mitre.oval:tst:4526"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8403" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-bg is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-bg"/>
        <description>Package OpenOffice_org-bg is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:29">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.517-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.902-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-bg is installed" test_ref="oval:org.mitre.oval:tst:4461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8389" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ru is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ru"/>
        <description>Package OpenOffice_org-ru is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:24">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.287-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.844-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ru is installed" test_ref="oval:org.mitre.oval:tst:4980"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8380" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-hu is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-hu"/>
        <description>Package OpenOffice_org1-hu is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.557-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.794-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-hu is installed" test_ref="oval:org.mitre.oval:tst:4532"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8357" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-cs is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-cs"/>
        <description>Package OpenOffice_org1-cs is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:02.976-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.691-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.369-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-cs is installed" test_ref="oval:org.mitre.oval:tst:4711"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8352" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ko is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ko"/>
        <description>Package OpenOffice_org-ko is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.726-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.634-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ko is installed" test_ref="oval:org.mitre.oval:tst:4941"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8342" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-gnome is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-gnome"/>
        <description>Package OpenOffice_org1-gnome is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.454-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.582-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.183-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-gnome is installed" test_ref="oval:org.mitre.oval:tst:4430"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8341" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-gu-IN is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-gu-IN"/>
        <description>Package OpenOffice_org-gu-IN is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:42">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.364-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.525-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.112-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-gu-IN is installed" test_ref="oval:org.mitre.oval:tst:4522"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8329" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-cy is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-cy"/>
        <description>Package OpenOffice_org-cy is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:44">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.695-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.359-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-cy is installed" test_ref="oval:org.mitre.oval:tst:5190"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8310" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-tr is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-tr"/>
        <description>Package OpenOffice_org1-tr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.083-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.307-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-tr is installed" test_ref="oval:org.mitre.oval:tst:4961"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8308" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-da is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-da"/>
        <description>Package OpenOffice_org1-da is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.025-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.256-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.763-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-da is installed" test_ref="oval:org.mitre.oval:tst:5012"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8288" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-vi is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-vi"/>
        <description>Package OpenOffice_org-vi is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:23">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.610-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.202-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.693-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-vi is installed" test_ref="oval:org.mitre.oval:tst:5155"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8269" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-zu is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-zu"/>
        <description>Package OpenOffice_org-zu is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:42">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.813-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:41.108-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.519-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-zu is installed" test_ref="oval:org.mitre.oval:tst:4496"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8264" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1 is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1"/>
        <description>Package OpenOffice_org1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:02.829-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:41.060-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1 is installed" test_ref="oval:org.mitre.oval:tst:4214"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8244" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-sk is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-sk"/>
        <description>Package OpenOffice_org-sk is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:38">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.342-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:40.996-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.387-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-sk is installed" test_ref="oval:org.mitre.oval:tst:4739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8228" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-hu is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-hu"/>
        <description>Package OpenOffice_org-hu is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:53">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.468-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:40.941-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-hu is installed" test_ref="oval:org.mitre.oval:tst:4235"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8222" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-mono is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-mono"/>
        <description>Package OpenOffice_org-mono is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:35">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.845-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:40.881-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.249-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-mono is installed" test_ref="oval:org.mitre.oval:tst:4809"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8215" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-fr is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-fr"/>
        <description>Package OpenOffice_org-fr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:29">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.202-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:40.821-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-fr is installed" test_ref="oval:org.mitre.oval:tst:4518"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2090" version="3" class="inventory">
      <metadata>
        <title>Novell Linux Desktop 9 is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:novell:linux_desktop:9"/>
        <description>Novell Linux Desktop 9 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T16:29:48">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-07-12T07:09:37.446-04:00">DRAFT</status_change>
            <modified comment="Removed unneeded platform information from the affected element and affected cpe list." date="2007-07-25T12:36:00.664-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Changed version value to 9" date="2007-07-25T12:58:00.106-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-08-10T13:33:40.954-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:30.062-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2090 - Fixed Definitions with missing platforms." date="2012-12-12T17:14:00.907-05:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-12-12T17:21:07.472-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:05.592-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Novell Linux Desktop 9 is installed" test_ref="oval:org.mitre.oval:tst:4075"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2044" version="3" class="inventory">
      <metadata>
        <title>SUSE Linux Professional 9.3 is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:novell:suse_linux:9.3::pro"/>
        <description>SUSE Linux Professional 9.3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T16:29:48">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-07-12T07:09:38.537-04:00">DRAFT</status_change>
            <modified comment="Removed unneeded platform information from the affected element and affected cpe list." date="2007-07-25T12:36:00.045-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-08-10T13:33:40.898-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:29.867-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2044 - Fixed Definitions with missing platforms." date="2012-12-12T17:14:00.907-05:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-12-12T17:20:54.378-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:05.347-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="SUSE Linux Professional 9.3 is installed" test_ref="oval:org.mitre.oval:tst:3212"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2027" version="3" class="inventory">
      <metadata>
        <title>SUSE Linux 10.0 is installed</title>
        <affected family="unix">
          <platform>SUSE Linux 10.0</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:novell:suse_linux:10.0"/>
        <description>SUSE Linux 10.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-28T06:18:50">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-07-10T21:08:30.126-04:00">DRAFT</status_change>
            <modified comment="Removed unneeded platform information from the affected element and affected cpe list." date="2007-07-25T13:03:00.573-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-08-10T13:33:40.841-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:29.546-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2027 - Fixed Definitions with missing platforms." date="2012-12-12T17:14:00.907-05:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-12-12T17:20:49.625-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:04.984-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="SUSE Linux 10.0 is installed" test_ref="oval:org.mitre.oval:tst:3693"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1366" version="3" class="inventory">
      <metadata>
        <title>SUSE Linux Desktop 1.0 is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Desktop 1.0</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:novell:suse_linux:1.0::desktop"/>
        <description>SUSE Linux Desktop 1.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T16:29:48">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-07-12T07:09:38.919-04:00">DRAFT</status_change>
            <modified comment="Removed unneeded platform information from the affected element and affected cpe list." date="2007-07-25T12:36:00.746-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-08-10T13:33:40.780-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:26.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1366 - Fixed Definitions with missing platforms." date="2012-12-12T17:14:00.907-05:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-12-12T17:21:13.681-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:00:30.233-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="SUSE Linux Desktop 1.0 is installed" test_ref="oval:org.mitre.oval:tst:3465"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:828" version="4" class="vulnerability">
      <metadata>
        <title>mod_python Web Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mod_python</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0973" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0973"/>
        <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.737-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.394-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.470-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T21:00:00.457-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:38.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_python version is less than 3.0.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:1612"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8275" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3871"/>
        <description>Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:09.897-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:15.872-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:02.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:07.846-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:59.358-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:33.691-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:36.780-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:42.438-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:37.464-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8272" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in rm(1) may Lead to Unauthorized Deletion of Files or Directories</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0895"/>
        <description>Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-06T11:50:11.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-08T21:33:23.977-04:00">DRAFT</status_change>
            <status_change date="2007-08-23T14:55:19.959-04:00">INTERIM</status_change>
            <status_change date="2007-09-10T14:45:27.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 124969-01 or later installed" test_ref="oval:org.mitre.oval:tst:4414" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 123372-02 or later installed" test_ref="oval:org.mitre.oval:tst:4946" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124244-01 or later installed" test_ref="oval:org.mitre.oval:tst:4215" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 124970-01 or later installed" test_ref="oval:org.mitre.oval:tst:4906" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 123373-02 or later installed" test_ref="oval:org.mitre.oval:tst:5133" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124245-01 or later installed" test_ref="oval:org.mitre.oval:tst:4576" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:827" version="4" class="vulnerability">
      <metadata>
        <title>Samba mksmboasswd Disabled Account Creation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Samba 3.0.0 and 3.0.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0082"/>
        <description>The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.833-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.214-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.279-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:57:22.153-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:38.639-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="samba version is less than 3.0.2-6.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1613"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:826" version="4" class="vulnerability">
      <metadata>
        <title>RedHat Enterprise 3 Code Execution and DoS Vulnerabilities in PWLib</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>PWLib</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0097"/>
        <description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Added a program_name element to rlt-217">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:26.501-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.025-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.033-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:59:24.680-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:38.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pwlib version is less than 1.4.7-7.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1614"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="a program is listening on TCP or UDP port 1720" negate="false" test_ref="oval:org.mitre.oval:tst:2320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8259" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2671" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2671"/>
        <description>The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:19.616-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:14.920-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:01.295-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:01.762-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:59.169-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:15.537-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:36.598-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:31.915-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:37.201-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:825" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Linux Kernel do_mremap Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mremap</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077"/>
        <description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.934-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.836-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="kernel version is less than 2.4.21-9.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1617"/>
          <criterion comment="kernel-smp version is less than 2.4.21-9.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1616"/>
          <criterion comment="kernel-hugemem version is less than 2.4.21-9.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1615"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8249" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer and Integer Overflow Vulnerabilities in Python (python(1)) May Lead to a Denial of Service (DoS) or Allow Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1721"/>
        <description>Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:10.283-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:03:56.147-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:16.164-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143506-01 or later installed" test_ref="oval:org.mitre.oval:tst:20998"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143507-01 or later installed" test_ref="oval:org.mitre.oval:tst:20927"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:823" version="2" class="vulnerability">
      <metadata>
        <title>Konqueror Cookie Access Restrictions Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0592"/>
        <description>Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.940-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdelibs version is less than 3.1-13" negate="false" test_ref="oval:org.mitre.oval:tst:1618"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/konqueror is executable">
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2655"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2654"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:822" version="2" class="vulnerability">
      <metadata>
        <title>Midnight Commander vfs_s_resolve_symlink BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Midnight Commander</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1023"/>
        <description>Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.070-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.376-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mc version is less than 4.6.0-7.9" negate="false" test_ref="oval:org.mitre.oval:tst:1622"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mc is executable">
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1621"/>
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1620"/>
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:821" version="2" class="vulnerability">
      <metadata>
        <title>slocate Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>slocate</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0848"/>
        <description>Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.635-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="slocate version is less than 2.7-2" negate="false" test_ref="oval:org.mitre.oval:tst:1625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/bin/slocate is setgid">
            <criterion comment="/usr/bin/slocate is setgid" negate="false" test_ref="oval:org.mitre.oval:tst:1624"/>
            <criterion comment="/usr/bin/slocate is setgid" negate="false" test_ref="oval:org.mitre.oval:tst:1623"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8208" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3799"/>
        <description>Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:42.221-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:14.495-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:00.780-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:820" version="2" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic directIM Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0008"/>
        <description>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:51.269-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.989-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8192" version="2" class="vulnerability">
      <metadata>
        <title>Integer Overflow Security Vulnerability in AES and RC4 Decryption in the Solaris Kerberos Crypto Library May Lead to Execution of Arbitrary Code or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4212"/>
        <description>Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:42.674-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:14.268-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:00.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 275530">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 141500-06 or later installed" test_ref="oval:org.mitre.oval:tst:20614"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 275530">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 141501-07 or later installed" test_ref="oval:org.mitre.oval:tst:20894"/>
          </criteria>
        </criteria>
        <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" test_ref="oval:org.mitre.oval:tst:1153"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:819" version="2" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic Extract Info Field Function BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0007"/>
        <description>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.253-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:818" version="2" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic BO Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0006"/>
        <description>Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:36.164-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:817" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox and Mozilla Shared Object Code Execution</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2270"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:815" version="4" class="vulnerability">
      <metadata>
        <title>Mailman Cross-site Scripting Vulnerability II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mailman</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0992" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0992"/>
        <description>Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:56.512-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.374-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.329-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:59:44.492-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:38.008-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mailman version is less than 2.1.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:1631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8134" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Solaris GNOME PDF Rendering Libraries May Lead to a Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3609" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3609"/>
        <description>Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.327-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:13.805-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:00.084-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120739-06 or later installed" test_ref="oval:org.mitre.oval:tst:21117"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120740-06 or later installed" test_ref="oval:org.mitre.oval:tst:20980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:813" version="4" class="vulnerability">
      <metadata>
        <title>Mailman Cross-site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mailman</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0965"/>
        <description>Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.431-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.077-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.329-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:59:44.212-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:37.725-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mailman version is less than 2.1.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:1631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:811" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Mutt BO in Index Menu</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0078"/>
        <description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:31.712-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:54.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mutt version is less than 1.4.1-3.3" negate="false" test_ref="oval:org.mitre.oval:tst:1634"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mutt is executable">
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2637"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2636"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:810" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 netpbm File Overwrite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>netpbm</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0924" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924"/>
        <description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:26.732-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:49.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="netpbm version is less than 9.24-11.30.1" negate="false" test_ref="oval:org.mitre.oval:tst:1637"/>
            <criterion comment="netpbm-devel version is less than 9.24-11.30.1" negate="false" test_ref="oval:org.mitre.oval:tst:1636"/>
            <criterion comment="netpbm-progs version is less than 9.24-11.30.1" negate="false" test_ref="oval:org.mitre.oval:tst:1635"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable configuration">
            <criteria operator="OR" comment="/usr/bin/411toppm is executable">
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2316"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2315"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2314"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/asciitopgm is executable">
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2313"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2312"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2311"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/atktopbm is executable">
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2310"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2309"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2308"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bioradtopgm is executable">
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2307"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2306"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2305"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bmptoppm is executable">
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2304"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2303"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2302"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/brushtopbm is executable">
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2301"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2300"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2299"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/cmuwmtopbm is executable">
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2298"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2297"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2296"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/eyuvtoppm is executable">
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2295"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2294"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2293"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fiascotopnm is executable">
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2292"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2291"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2290"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fitstopnm is executable">
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2289"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2288"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2287"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fstopgm is executable">
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2286"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2285"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2284"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/g3topbm is executable">
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2283"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2282"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2281"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopbm is executable">
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2280"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2279"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2278"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopnm is executable">
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2277"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2276"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2275"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/giftopnm is executable">
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2274"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2273"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2272"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gouldtoppm is executable">
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2271"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2270"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2269"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hipstopgm is executable">
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2268"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2267"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2266"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hpcdtoppm is executable">
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2265"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2264"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2263"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/icontopbm is executable">
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2262"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2261"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2260"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ilbmtoppm is executable">
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2259"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2258"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2257"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/imgtoppm is executable">
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2256"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2255"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2254"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/jpegtopnm is executable">
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2253"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2252"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2251"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/leaftoppm is executable">
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2250"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2249"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2248"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/lispmtopgm is executable">
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2247"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2246"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2245"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/macptopbm is executable">
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2244"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2243"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2242"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mdatopbm is executable">
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2241"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2240"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2239"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mgrtopbm is executable">
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2238"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2237"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2236"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mtvtoppm is executable">
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2235"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2234"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2233"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/neotoppm is executable">
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2232"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2231"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2230"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/palmtopnm is executable">
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2229"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2228"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2227"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamchannel is executable">
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2226"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2225"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2224"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamcut is executable">
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2223"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2222"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2221"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamdeinterlace is executable">
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2220"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2219"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2218"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamfile is executable">
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2217"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2216"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2215"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamoil is executable">
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2214"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2213"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2212"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamstretch is executable">
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2211"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2210"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2209"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamtopnm is executable">
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2208"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2207"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2206"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmclean is executable">
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2205"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2204"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2203"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmlife is executable">
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2202"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2201"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2200"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmake is executable">
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2199"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2198"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2197"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmask is executable">
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2196"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2195"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2194"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpage is executable">
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2193"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2192"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2191"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpscale is executable">
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2190"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2189"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2188"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmreduce is executable">
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2187"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2186"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2185"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtext is executable">
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2184"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2183"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2182"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto10x is executable">
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2181"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2180"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2179"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto4425 is executable">
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2178"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2177"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2176"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoascii is executable">
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2175"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2174"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2173"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoatk is executable">
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2172"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2171"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2170"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtobbnbg is executable">
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2169"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2168"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2167"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtocmuwm is executable">
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2166"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2165"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2164"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepsi is executable">
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2163"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2162"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2161"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepson is executable">
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2160"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2159"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2158"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtog3 is executable">
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2157"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2156"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2155"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogem is executable">
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2154"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2153"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2152"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogo is executable">
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2151"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2150"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2149"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoicon is executable">
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2148"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2147"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2146"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolj is executable">
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2145"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2144"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2143"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoln03 is executable">
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2142"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2141"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2140"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolps is executable">
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2139"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2138"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2137"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomacp is executable">
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2136"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2135"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2134"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomda is executable">
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2133"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2132"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2131"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomgr is executable">
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2130"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2129"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2128"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtonokia is executable">
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2127"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2126"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2125"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopgm is executable">
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2124"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2123"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2122"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopi3 is executable">
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2121"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2120"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2119"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopk is executable">
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2118"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2117"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2116"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoplot is executable">
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2115"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2114"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2113"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoppa is executable">
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2112"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2111"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2110"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopsg3 is executable">
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2109"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2108"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2107"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoptx is executable">
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2106"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2105"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2104"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtowbmp is executable">
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2103"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2102"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2101"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtox10bm is executable">
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2100"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2099"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2098"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoxbm is executable">
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2097"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2096"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2095"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoybm is executable">
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2094"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2093"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2092"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtozinc is executable">
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2091"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2090"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2089"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmupc is executable">
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2088"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2087"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2086"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pcxtoppm is executable">
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2085"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2084"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2083"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmbentley is executable">
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2082"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2081"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2080"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmcrater is executable">
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2079"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2078"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2077"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmedge is executable">
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2076"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2075"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2074"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmenhance is executable">
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2073"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2072"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2071"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmhist is executable">
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2070"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2069"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2068"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmkernel is executable">
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2067"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2066"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2065"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnoise is executable">
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2064"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2063"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2062"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnorm is executable">
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2061"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2060"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2059"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmoil is executable">
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2058"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2057"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2056"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmramp is executable">
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2055"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2054"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2053"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmslice is executable">
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2052"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2051"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2050"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtexture is executable">
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2049"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2048"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2047"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtofs is executable">
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2046"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2045"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2044"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtolispm is executable">
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2043"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2042"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2041"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtopbm is executable">
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2040"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2039"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2038"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtoppm is executable">
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2037"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2036"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2035"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi1toppm is executable">
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2034"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2033"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2032"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi3topbm is executable">
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2031"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2030"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2029"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pjtoppm is executable">
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2028"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2027"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2026"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pktopbm is executable">
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2025"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2024"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2023"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pngtopnm is executable">
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2022"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2021"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2020"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmalias is executable">
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2019"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2018"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2017"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmarith is executable">
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2016"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2015"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2014"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcat is executable">
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2013"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2012"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2011"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcolormap is executable">
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2010"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2009"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2008"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcomp is executable">
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2007"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2006"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2005"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmconvol is executable">
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2004"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2003"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2002"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcrop is executable">
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2001"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2000"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1999"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcut is executable">
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1998"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1997"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1996"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmdepth is executable">
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1995"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1994"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1993"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmenlarge is executable">
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1992"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1991"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1990"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmfile is executable">
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1989"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1988"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1987"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmflip is executable">
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1986"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1985"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1984"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmgamma is executable">
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1983"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1982"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1981"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhisteq is executable">
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1980"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1979"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1978"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhistmap is executable">
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1977"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1976"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1975"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminterp is executable">
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1974"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1973"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1972"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminvert is executable">
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1971"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1970"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1969"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmmontage is executable">
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1968"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1967"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1966"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnlfilt is executable">
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1965"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1964"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1963"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnoraw is executable">
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1962"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1961"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1960"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpad is executable">
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1959"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1958"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1957"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpaste is executable">
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1956"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1955"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1954"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpsnr is executable">
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1953"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1952"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1951"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmremap is executable">
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1950"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1949"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1948"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmrotate is executable">
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1947"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1946"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1945"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscale is executable">
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1944"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1943"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1942"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopict is executable">
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1941"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1940"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1939"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopj is executable">
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1938"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1937"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1936"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopjxl is executable">
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1935"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1934"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1933"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopuzz is executable">
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1932"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1931"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1930"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtorgb3 is executable">
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1929"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1928"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1927"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtosixel is executable">
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1926"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1925"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1924"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtotga is executable">
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1923"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1922"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1921"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtouil is executable">
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1920"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1919"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1918"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtowinicon is executable">
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1917"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1916"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1915"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoxpm is executable">
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1914"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1913"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1912"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuv is executable">
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1911"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1910"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1909"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuvsplit is executable">
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1908"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1907"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1906"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtv is executable">
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1905"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1904"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1903"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/psidtopgm is executable">
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1902"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1901"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1900"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pstopnm is executable">
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1899"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1898"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1897"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/qrttoppm is executable">
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1896"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1895"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1894"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rasttopnm is executable">
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1893"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1892"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1891"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtopgm is executable">
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1890"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1889"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1888"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtoppm is executable">
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1887"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1886"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1885"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rgb3toppm is executable">
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1884"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1883"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1882"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rletopnm is executable">
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1881"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1880"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1879"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sbigtopgm is executable">
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1878"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1877"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1876"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sgitopnm is executable">
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1875"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1874"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1873"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sirtopnm is executable">
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1872"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1871"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1870"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sldtoppm is executable">
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1869"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1868"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1867"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spctoppm is executable">
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1866"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1865"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1864"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spottopgm is executable">
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1863"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1862"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1861"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sputoppm is executable">
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1860"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1859"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1858"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tgatoppm is executable">
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1857"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1856"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1855"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/thinkjettopbm is executable">
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1854"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1853"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1852"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tifftopnm is executable">
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1851"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1850"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1849"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/wbmptopbm is executable">
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1848"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1847"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1846"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/winicontoppm is executable">
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1845"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1844"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1843"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xbmtopbm is executable">
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1842"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1841"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1840"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ximtoppm is executable">
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1839"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1838"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1837"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xpmtoppm is executable">
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1836"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1835"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1834"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xvminitoppm is executable">
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1833"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1832"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1831"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xwdtopnm is executable">
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1830"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1829"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1828"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ybmtopbm is executable">
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1827"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1826"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1825"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvsplittoppm is executable">
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1824"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1823"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1822"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvtoppm is executable">
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1821"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1820"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1819"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/zeisstopnm is executable">
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1818"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1817"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1816"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscalefixed is executable">
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1815"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1814"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1813"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmshear is executable">
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1812"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1811"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1810"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsmooth is executable">
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1809"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1808"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1807"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsplit is executable">
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1806"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1805"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1804"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtile is executable">
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1803"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1802"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1801"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoddif is executable">
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1800"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1799"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1798"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofiasco is executable">
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1797"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1796"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1795"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofits is executable">
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1794"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1793"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1792"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtojpeg is executable">
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1791"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1790"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1789"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopalm is executable">
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1788"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1787"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1786"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoplainpnm is executable">
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1785"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1784"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1783"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopng is executable">
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1782"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1781"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1780"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtops is executable">
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1779"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1778"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1777"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorast is executable">
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1776"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1775"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1774"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorle is executable">
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1773"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1772"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1771"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosgi is executable">
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1770"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1769"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1768"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosir is executable">
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1767"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1766"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1765"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiff is executable">
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1764"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1763"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1762"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiffcmyk is executable">
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1761"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1760"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1759"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoxwd is executable">
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1758"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1757"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1756"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppm3d is executable">
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1755"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1754"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1753"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmbrighten is executable">
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1752"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1751"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1750"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmchange is executable">
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1749"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1748"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1747"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcie is executable">
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1746"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1745"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1744"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolormask is executable">
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1743"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1742"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1741"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolors is executable">
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1740"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1739"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1738"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdim is executable">
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1737"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1736"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1735"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdist is executable">
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1734"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1733"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1732"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdither is executable">
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1731"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1730"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1729"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmflash is executable">
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1728"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1727"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1726"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmforge is executable">
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1725"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1724"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1723"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmhist is executable">
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1722"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1721"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1720"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmlabel is executable">
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1719"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1718"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1717"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmake is executable">
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1716"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1715"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1714"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmix is executable">
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1713"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1712"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1711"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmnorm is executable">
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1710"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1709"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1708"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmntsc is executable">
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1707"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1706"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1705"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmpat is executable">
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1704"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1703"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1702"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmquant is executable">
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1701"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1700"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1699"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmqvga is executable">
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1698"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1697"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1696"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmrelief is executable">
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1695"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1694"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1693"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmshift is executable">
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1692"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1691"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1690"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmspread is executable">
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1689"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1688"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1687"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoacad is executable">
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1686"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1685"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1684"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtobmp is executable">
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1683"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1682"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1681"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoeyuv is executable">
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1680"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1679"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1678"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtogif is executable">
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1677"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1676"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1675"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoicr is executable">
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1674"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1673"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1672"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoilbm is executable">
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1671"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1670"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1669"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtojpeg is executable">
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1668"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1667"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1666"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoleaf is executable">
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1665"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1664"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1663"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtolj is executable">
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1662"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1661"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1660"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtomitsu is executable">
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1659"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1658"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1657"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtompeg is executable">
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1656"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1655"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1654"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoneo is executable">
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1653"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1652"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1651"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopcx is executable">
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1650"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1649"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1648"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopgm is executable">
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1647"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1646"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1645"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopi1 is executable">
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1644"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1643"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1642"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:809" version="2" class="vulnerability">
      <metadata>
        <title>XFree86 Font File Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0106"/>
        <description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:21.877-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:47.539-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:808" version="5" class="vulnerability">
      <metadata>
        <title>RHE4 XBL Script Security Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2261"/>
        <description>Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11366 - Updated CPE reference, updated regular expression" date="2011-02-17T13:29:00.547-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-02-17T13:31:08.313-05:00">INTERIM</status_change>
            <status_change date="2011-03-07T04:00:15.721-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11366 - Corrected - right version for brlapi and brlapi-devel as specified by RHSA-2010:0181-5" date="2013-03-18T12:26:00.995-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-18T12:31:11.401-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:49.461-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8073" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2674" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2674"/>
        <description>Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:21.885-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:12.245-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:58.399-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:48.177-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:58.701-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:35:34.721-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:36.406-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:12.618-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:36.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:807" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat XFree86 Buffer Overflow in ReadFontAlias II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0084"/>
        <description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.326-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:47.331-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:806" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat XFree86 Buffer Overflow in ReadFontAlias</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083"/>
        <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:23.593-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:47.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:804" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat netpbm File Overwrite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>netpbm</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0924" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924"/>
        <description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:00.100-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:42.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="netpbm version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2319"/>
            <criterion comment="netpbm-devel version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2318"/>
            <criterion comment="netpbm-progs version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2317"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable configuration">
            <criteria operator="OR" comment="/usr/bin/411toppm is executable">
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2316"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2315"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2314"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/asciitopgm is executable">
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2313"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2312"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2311"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/atktopbm is executable">
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2310"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2309"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2308"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bioradtopgm is executable">
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2307"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2306"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2305"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bmptoppm is executable">
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2304"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2303"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2302"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/brushtopbm is executable">
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2301"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2300"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2299"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/cmuwmtopbm is executable">
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2298"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2297"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2296"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/eyuvtoppm is executable">
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2295"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2294"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2293"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fiascotopnm is executable">
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2292"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2291"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2290"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fitstopnm is executable">
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2289"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2288"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2287"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fstopgm is executable">
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2286"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2285"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2284"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/g3topbm is executable">
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2283"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2282"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2281"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopbm is executable">
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2280"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2279"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2278"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopnm is executable">
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2277"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2276"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2275"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/giftopnm is executable">
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2274"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2273"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2272"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gouldtoppm is executable">
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2271"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2270"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2269"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hipstopgm is executable">
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2268"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2267"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2266"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hpcdtoppm is executable">
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2265"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2264"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2263"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/icontopbm is executable">
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2262"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2261"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2260"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ilbmtoppm is executable">
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2259"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2258"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2257"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/imgtoppm is executable">
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2256"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2255"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2254"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/jpegtopnm is executable">
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2253"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2252"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2251"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/leaftoppm is executable">
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2250"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2249"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2248"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/lispmtopgm is executable">
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2247"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2246"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2245"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/macptopbm is executable">
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2244"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2243"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2242"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mdatopbm is executable">
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2241"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2240"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2239"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mgrtopbm is executable">
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2238"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2237"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2236"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mtvtoppm is executable">
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2235"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2234"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2233"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/neotoppm is executable">
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2232"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2231"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2230"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/palmtopnm is executable">
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2229"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2228"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2227"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamchannel is executable">
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2226"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2225"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2224"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamcut is executable">
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2223"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2222"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2221"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamdeinterlace is executable">
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2220"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2219"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2218"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamfile is executable">
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2217"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2216"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2215"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamoil is executable">
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2214"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2213"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2212"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamstretch is executable">
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2211"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2210"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2209"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamtopnm is executable">
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2208"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2207"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2206"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmclean is executable">
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2205"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2204"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2203"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmlife is executable">
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2202"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2201"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2200"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmake is executable">
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2199"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2198"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2197"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmask is executable">
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2196"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2195"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2194"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpage is executable">
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2193"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2192"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2191"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpscale is executable">
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2190"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2189"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2188"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmreduce is executable">
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2187"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2186"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2185"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtext is executable">
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2184"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2183"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2182"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto10x is executable">
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2181"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2180"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2179"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto4425 is executable">
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2178"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2177"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2176"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoascii is executable">
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2175"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2174"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2173"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoatk is executable">
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2172"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2171"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2170"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtobbnbg is executable">
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2169"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2168"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2167"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtocmuwm is executable">
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2166"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2165"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2164"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepsi is executable">
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2163"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2162"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2161"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepson is executable">
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2160"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2159"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2158"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtog3 is executable">
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2157"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2156"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2155"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogem is executable">
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2154"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2153"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2152"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogo is executable">
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2151"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2150"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2149"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoicon is executable">
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2148"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2147"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2146"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolj is executable">
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2145"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2144"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2143"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoln03 is executable">
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2142"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2141"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2140"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolps is executable">
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2139"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2138"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2137"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomacp is executable">
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2136"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2135"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2134"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomda is executable">
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2133"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2132"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2131"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomgr is executable">
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2130"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2129"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2128"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtonokia is executable">
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2127"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2126"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2125"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopgm is executable">
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2124"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2123"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2122"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopi3 is executable">
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2121"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2120"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2119"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopk is executable">
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2118"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2117"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2116"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoplot is executable">
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2115"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2114"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2113"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoppa is executable">
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2112"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2111"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2110"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopsg3 is executable">
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2109"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2108"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2107"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoptx is executable">
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2106"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2105"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2104"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtowbmp is executable">
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2103"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2102"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2101"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtox10bm is executable">
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2100"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2099"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2098"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoxbm is executable">
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2097"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2096"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2095"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoybm is executable">
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2094"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2093"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2092"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtozinc is executable">
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2091"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2090"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2089"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmupc is executable">
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2088"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2087"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2086"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pcxtoppm is executable">
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2085"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2084"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2083"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmbentley is executable">
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2082"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2081"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2080"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmcrater is executable">
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2079"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2078"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2077"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmedge is executable">
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2076"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2075"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2074"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmenhance is executable">
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2073"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2072"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2071"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmhist is executable">
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2070"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2069"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2068"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmkernel is executable">
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2067"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2066"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2065"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnoise is executable">
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2064"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2063"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2062"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnorm is executable">
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2061"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2060"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2059"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmoil is executable">
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2058"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2057"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2056"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmramp is executable">
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2055"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2054"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2053"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmslice is executable">
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2052"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2051"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2050"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtexture is executable">
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2049"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2048"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2047"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtofs is executable">
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2046"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2045"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2044"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtolispm is executable">
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2043"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2042"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2041"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtopbm is executable">
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2040"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2039"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2038"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtoppm is executable">
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2037"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2036"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2035"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi1toppm is executable">
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2034"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2033"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2032"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi3topbm is executable">
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2031"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2030"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2029"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pjtoppm is executable">
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2028"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2027"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2026"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pktopbm is executable">
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2025"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2024"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2023"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pngtopnm is executable">
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2022"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2021"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2020"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmalias is executable">
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2019"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2018"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2017"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmarith is executable">
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2016"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2015"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2014"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcat is executable">
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2013"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2012"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2011"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcolormap is executable">
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2010"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2009"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2008"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcomp is executable">
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2007"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2006"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2005"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmconvol is executable">
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2004"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2003"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2002"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcrop is executable">
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2001"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2000"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1999"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcut is executable">
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1998"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1997"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1996"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmdepth is executable">
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1995"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1994"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1993"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmenlarge is executable">
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1992"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1991"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1990"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmfile is executable">
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1989"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1988"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1987"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmflip is executable">
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1986"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1985"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1984"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmgamma is executable">
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1983"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1982"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1981"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhisteq is executable">
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1980"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1979"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1978"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhistmap is executable">
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1977"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1976"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1975"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminterp is executable">
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1974"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1973"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1972"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminvert is executable">
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1971"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1970"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1969"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmmontage is executable">
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1968"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1967"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1966"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnlfilt is executable">
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1965"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1964"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1963"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnoraw is executable">
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1962"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1961"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1960"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpad is executable">
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1959"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1958"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1957"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpaste is executable">
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1956"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1955"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1954"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpsnr is executable">
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1953"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1952"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1951"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmremap is executable">
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1950"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1949"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1948"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmrotate is executable">
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1947"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1946"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1945"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscale is executable">
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1944"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1943"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1942"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopict is executable">
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1941"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1940"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1939"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopj is executable">
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1938"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1937"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1936"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopjxl is executable">
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1935"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1934"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1933"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopuzz is executable">
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1932"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1931"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1930"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtorgb3 is executable">
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1929"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1928"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1927"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtosixel is executable">
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1926"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1925"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1924"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtotga is executable">
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1923"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1922"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1921"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtouil is executable">
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1920"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1919"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1918"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtowinicon is executable">
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1917"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1916"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1915"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoxpm is executable">
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1914"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1913"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1912"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuv is executable">
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1911"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1910"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1909"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuvsplit is executable">
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1908"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1907"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1906"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtv is executable">
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1905"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1904"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1903"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/psidtopgm is executable">
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1902"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1901"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1900"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pstopnm is executable">
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1899"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1898"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1897"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/qrttoppm is executable">
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1896"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1895"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1894"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rasttopnm is executable">
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1893"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1892"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1891"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtopgm is executable">
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1890"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1889"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1888"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtoppm is executable">
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1887"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1886"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1885"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rgb3toppm is executable">
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1884"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1883"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1882"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rletopnm is executable">
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1881"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1880"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1879"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sbigtopgm is executable">
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1878"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1877"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1876"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sgitopnm is executable">
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1875"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1874"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1873"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sirtopnm is executable">
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1872"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1871"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1870"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sldtoppm is executable">
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1869"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1868"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1867"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spctoppm is executable">
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1866"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1865"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1864"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spottopgm is executable">
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1863"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1862"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1861"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sputoppm is executable">
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1860"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1859"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1858"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tgatoppm is executable">
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1857"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1856"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1855"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/thinkjettopbm is executable">
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1854"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1853"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1852"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tifftopnm is executable">
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1851"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1850"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1849"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/wbmptopbm is executable">
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1848"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1847"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1846"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/winicontoppm is executable">
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1845"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1844"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1843"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xbmtopbm is executable">
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1842"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1841"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1840"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ximtoppm is executable">
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1839"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1838"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1837"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xpmtoppm is executable">
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1836"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1835"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1834"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xvminitoppm is executable">
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1833"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1832"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1831"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xwdtopnm is executable">
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1830"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1829"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1828"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ybmtopbm is executable">
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1827"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1826"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1825"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvsplittoppm is executable">
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1824"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1823"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1822"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvtoppm is executable">
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1821"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1820"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1819"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/zeisstopnm is executable">
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1818"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1817"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1816"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscalefixed is executable">
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1815"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1814"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1813"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmshear is executable">
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1812"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1811"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1810"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsmooth is executable">
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1809"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1808"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1807"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsplit is executable">
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1806"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1805"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1804"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtile is executable">
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1803"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1802"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1801"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoddif is executable">
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1800"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1799"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1798"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofiasco is executable">
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1797"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1796"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1795"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofits is executable">
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1794"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1793"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1792"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtojpeg is executable">
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1791"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1790"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1789"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopalm is executable">
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1788"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1787"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1786"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoplainpnm is executable">
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1785"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1784"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1783"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopng is executable">
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1782"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1781"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1780"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtops is executable">
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1779"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1778"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1777"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorast is executable">
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1776"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1775"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1774"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorle is executable">
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1773"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1772"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1771"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosgi is executable">
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1770"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1769"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1768"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosir is executable">
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1767"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1766"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1765"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiff is executable">
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1764"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1763"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1762"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiffcmyk is executable">
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1761"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1760"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1759"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoxwd is executable">
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1758"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1757"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1756"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppm3d is executable">
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1755"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1754"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1753"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmbrighten is executable">
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1752"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1751"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1750"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmchange is executable">
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1749"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1748"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1747"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcie is executable">
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1746"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1745"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1744"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolormask is executable">
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1743"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1742"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1741"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolors is executable">
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1740"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1739"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1738"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdim is executable">
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1737"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1736"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1735"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdist is executable">
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1734"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1733"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1732"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdither is executable">
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1731"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1730"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1729"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmflash is executable">
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1728"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1727"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1726"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmforge is executable">
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1725"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1724"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1723"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmhist is executable">
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1722"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1721"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1720"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmlabel is executable">
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1719"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1718"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1717"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmake is executable">
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1716"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1715"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1714"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmix is executable">
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1713"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1712"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1711"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmnorm is executable">
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1710"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1709"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1708"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmntsc is executable">
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1707"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1706"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1705"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmpat is executable">
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1704"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1703"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1702"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmquant is executable">
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1701"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1700"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1699"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmqvga is executable">
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1698"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1697"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1696"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmrelief is executable">
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1695"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1694"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1693"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmshift is executable">
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1692"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1691"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1690"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmspread is executable">
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1689"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1688"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1687"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoacad is executable">
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1686"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1685"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1684"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtobmp is executable">
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1683"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1682"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1681"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoeyuv is executable">
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1680"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1679"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1678"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtogif is executable">
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1677"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1676"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1675"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoicr is executable">
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1674"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1673"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1672"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoilbm is executable">
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1671"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1670"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1669"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtojpeg is executable">
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1668"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1667"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1666"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoleaf is executable">
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1665"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1664"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1663"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtolj is executable">
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1662"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1661"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1660"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtomitsu is executable">
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1659"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1658"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1657"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtompeg is executable">
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1656"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1655"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1654"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoneo is executable">
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1653"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1652"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1651"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopcx is executable">
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1650"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1649"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1648"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopgm is executable">
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1647"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1646"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1645"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopi1 is executable">
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1644"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1643"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1642"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:803" version="4" class="vulnerability">
      <metadata>
        <title>RedHat Code Execution and DoS Vulnerabilities in PWLib</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>PWLib</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0097"/>
        <description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Added a program_name element to rlt-217">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.185-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:40.547-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.033-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:59:24.750-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:37.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pwlib version is less than 1.4.7-4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2321"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="a program is listening on TCP or UDP port 1720" negate="false" test_ref="oval:org.mitre.oval:tst:2320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8022" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2670" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2670"/>
        <description>The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:18.830-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:10.076-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:57.052-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:55.994-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:58.515-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:35:56.345-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:36.220-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:23.651-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:36.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:80" version="3" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE ToolTalk Database Symbolic Link Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Common Desktop Environment</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0678"/>
        <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:28.768-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:40.359-04:00">ACCEPTED</status_change>
            <modified comment="Fixed incorrect user_id element value in process_state.  Incorrect value was 'root', updated to value of '0'." date="2010-09-02T15:11:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T15:13:53.319-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:37.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 107893-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2969"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7986" version="10" class="vulnerability">
      <metadata>
        <title>HP-UX Running VRTSweb, Remote Execution of Arbitrary Code, Increase of Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3027"/>
        <description>VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:40.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:04.616-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:09.612-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:56.592-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:02.354-05:00">INTERIM</status_change>
            <status_change date="2014-03-10T04:00:52.068-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:17.962-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:36.114-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:33.446-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:36.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02480">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="VRTSweb.VRTSWEB is installed" test_ref="oval:org.mitre.oval:tst:20656"/>
          <criteria negate="true" operator="OR" comment="Patch PHCO_40519 and PHCO_40520 are installed">
            <criterion comment="Patch PHCO_40519 is installed" test_ref="oval:org.mitre.oval:tst:21311"/>
            <criterion comment="Patch PHCO_40520 is installed" test_ref="oval:org.mitre.oval:tst:21357"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02480">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="VRTSweb.VRTSWEB is installed" test_ref="oval:org.mitre.oval:tst:20656"/>
          <criterion negate="true" comment="Patch PHCO_40518 is installed" test_ref="oval:org.mitre.oval:tst:21249"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7973" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer 3.0 (SSLv3) Protocols Involving Handshake Renegotiation Affects Applications Utilizing Network Security Services (NSS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:08.599-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:02:19.988-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:13.620-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 273350">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 119209-22 or later installed" test_ref="oval:org.mitre.oval:tst:20450"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 273350">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 119211-22 or later installed" test_ref="oval:org.mitre.oval:tst:21074"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273350">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119213-21 or later installed" test_ref="oval:org.mitre.oval:tst:20949"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 273350">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119212-22 or later installed" test_ref="oval:org.mitre.oval:tst:21052"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273350">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119214-21 or later installed" test_ref="oval:org.mitre.oval:tst:20806"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7913" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3875"/>
        <description>The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:12.989-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:07.963-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:54.930-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:04.298-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:57.816-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:22.750-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:35.901-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:16.457-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:36.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7902" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3798"/>
        <description>Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:42.072-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:07.557-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:54.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:79" version="3" class="vulnerability">
      <metadata>
        <title>Solaris 8 RWall Daemon Syslog Format String Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>rpc.rwalld</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0573"/>
        <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:16:00.472-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:04.742-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:40.174-04:00">ACCEPTED</status_change>
            <modified comment="Fixed incorrect user_id element value in process_state.  Incorrect value was 'root', updated to value of '0'." date="2010-09-02T15:11:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T15:13:54.569-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:36.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.rwalld exists" negate="false" test_ref="oval:org.mitre.oval:tst:3032"/>
          <criterion comment="Patch 112846-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2970"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.rwalld" negate="false" test_ref="oval:org.mitre.oval:tst:3030"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.rwalld executable">
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3029"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3028"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3027"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:785" version="7" class="vulnerability">
      <metadata>
        <title>HP-UX usermod(1M) Local Unauthorized Access.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-05-07T12:00:00.048-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-07T12:01:40.074-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:52.817-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.466-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.680-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02102" date="2008-07-14T10:21:00.322-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:22:19.346-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.912-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:11.708-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:57.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
            <criterion comment="OS-Core.SYS2-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:7877"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_34764 is installed" test_ref="oval:org.mitre.oval:tst:8277"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
          <criterion negate="true" comment="Patch PHCO_33142 is installed" test_ref="oval:org.mitre.oval:tst:8598"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
          <criterion negate="true" comment="Patch PHCO_34763 is installed" test_ref="oval:org.mitre.oval:tst:8081"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7836" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Solaris GNOME PDF Rendering Libraries May Lead to a Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3606" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3606"/>
        <description>Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.158-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:05.558-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:52.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120739-06 or later installed" test_ref="oval:org.mitre.oval:tst:21117"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120740-06 or later installed" test_ref="oval:org.mitre.oval:tst:20980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:781" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 InstallVersion.compareTo() DoS and Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2265"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7800" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer and Integer Overflow Vulnerabilities in Python (python(1)) May Lead to a Denial of Service (DoS) or Allow Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1679"/>
        <description>Multiple integer overflows in imageop.c in Python before 2.5.3 allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted images that trigger heap-based buffer overflows.  NOTE: this issue is due to an incomplete fix for CVE-2007-4965.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:09.965-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:01:17.596-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:13.347-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143506-01 or later installed" test_ref="oval:org.mitre.oval:tst:20998"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143507-01 or later installed" test_ref="oval:org.mitre.oval:tst:20927"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7779" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in GNU tar (see gtar(1)) May Lead to Files Being Overwritten, Execution of Arbitrary Code, or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4131"/>
        <description>Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-26T14:24:08.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:04.503-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:03.879-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:50.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 273551">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 118191-04 or later installed" test_ref="oval:org.mitre.oval:tst:21169"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273551">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139099-03 or later installed" test_ref="oval:org.mitre.oval:tst:20999"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 273551">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 118192-04 or later installed" test_ref="oval:org.mitre.oval:tst:21124"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273551">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139100-03 or later installed" test_ref="oval:org.mitre.oval:tst:21085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7763" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3796"/>
        <description>Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a "data injection vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.736-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:02.603-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:49.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7750" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3867" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3867"/>
        <description>Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:07.668-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:01.814-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:48.760-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:57.963-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:57.324-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:03.050-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:35.586-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:26.444-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:35.549-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7731" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Solaris GNOME PDF Rendering Libraries May Lead to a Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3605" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3605"/>
        <description>Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/.  NOTE: this may overlap CVE-2009-0791.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:40.963-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:01.071-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:47.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120739-06 or later installed" test_ref="oval:org.mitre.oval:tst:21117"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120740-06 or later installed" test_ref="oval:org.mitre.oval:tst:20980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:773" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Mozilla top.focus() Cross-Site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2266"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7723" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2672"/>
        <description>The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:20.390-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:59.776-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:46.519-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:47.769-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:56.857-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:35:32.493-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:35.359-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:11.702-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:35.285-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:772" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Usermod Local Unauthorized Access Vulnerability instead of usermod Recursive Ownership Error.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:27:00.650-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:42:53.692-04:00">INTERIM</status_change>
            <modified comment="Updated definition title. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:42:00.035-04:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-04-10T13:44:28.730-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:767" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.10.01, B.10.10)</title>
        <affected family="unix">
          <platform>HP-UX 10</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.325-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.571-04:00">ACCEPTED</status_change>
            <modified comment="Updated the datatype from 'string' to 'fileset_revision' to match Schematron rules." date="2010-09-02T11:23:00.832-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T12:46:32.567-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:36.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.10.20) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2373"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2372"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2371"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2370"/>
        </criteria>
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.01 or 10.10">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.01">
            <criteria operator="AND" comment="700 Series OS Release 10.01">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:2369"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.01">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:2369"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.10">
            <criteria operator="AND" comment="700 Series OS Release 10.10">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:2368"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.10">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:2368"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_23947 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2367"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:766" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX Trusted Mode remshd, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3565"/>
        <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.246-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.446-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02072" date="2008-07-14T10:21:00.631-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:24:15.648-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.468-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:09.107-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:56.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_33791 is installed" test_ref="oval:org.mitre.oval:tst:8349"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_33790 is installed" test_ref="oval:org.mitre.oval:tst:8118"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8005"/>
          <criterion negate="true" comment="Patch PHNE_33792 is installed" test_ref="oval:org.mitre.oval:tst:8139"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7652" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3292"/>
        <description>Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:48.291-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:54.549-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:56.406-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:57.282-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:56.556-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:00.956-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:35.218-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:25.442-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:35.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:765" version="3" class="vulnerability">
      <metadata>
        <title>GNU GZip CHMod File Permission Modification Race ConditionWeakness</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0988"/>
        <description>Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.441-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.590-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:47:00.641-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:48:04.662-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:27.180-04:00">ACCEPTED</status_change>
            <modified comment="Corrected sparc criterion that was intended to be x86." date="2009-07-17T11:09:00.290-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:19:33.298-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:04.095-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112668-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4005"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112669-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4070"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116340-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3666"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 116341-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3778"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120719-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3295"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120720-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:760" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Byte-range DoS Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
        <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7594" version="3" class="vulnerability">
      <metadata>
        <title>Solaris and OpenSolaris products kernel component vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0890"/>
        <description>Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_01 through snv_98 allows local users to affect availability via unknown vectors related to the Kernel.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-21T14:34:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-22T13:39:57.735-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:57.654-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:44.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 242386">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138888-01 or later installed" test_ref="oval:org.mitre.oval:tst:11384"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 242386">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138889-01 or later installed" test_ref="oval:org.mitre.oval:tst:11447"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:759" version="5" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla Framed Site Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1937" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1937"/>
        <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11366 - Updated CPE reference, updated regular expression" date="2011-02-17T13:29:00.547-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-02-17T13:31:08.961-05:00">INTERIM</status_change>
            <status_change date="2011-03-07T04:00:15.412-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11366 - Corrected - right version for brlapi and brlapi-devel as specified by RHSA-2010:0181-5" date="2013-03-18T12:26:00.995-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-18T12:31:12.572-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:48.883-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7550" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2798"/>
        <description>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:35:23.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:55.148-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:52.073-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:55.203-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:05.473-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:56.078-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:28.133-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:35.061-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:39.149-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:34.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41168 is installed" test_ref="oval:org.mitre.oval:tst:20503"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41167 is installed" test_ref="oval:org.mitre.oval:tst:21355"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41166 is installed" test_ref="oval:org.mitre.oval:tst:21374"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21255"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20686"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21334"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21081"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20956"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21369"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21120"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21060"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21383"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21317"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20710"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21337"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21431"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21330"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:755" version="2" class="vulnerability">
      <metadata>
        <title>Sun Java System Access Manager Local Authentication Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <platform>Sun Solaris 9</platform>
          <product>Access Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0531"/>
        <description>Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.102-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.406-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:52:00.016-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:53:06.046-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:26.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="x86" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
        <criterion comment="Sun Java System Access Manager 7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3551"/>
        <criterion comment="Patch 120955-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3363"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:75" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.12 Vulnerability in DCERPC Dissector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0428" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0428"/>
        <description>Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.279-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:749" version="1" class="vulnerability">
      <metadata>
        <title>bzip2 Decompression Bomb</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>bzip2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1260"/>
        <description>bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" negate="false" test_ref="oval:org.mitre.oval:tst:2386"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/bzip2 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2385"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7459" version="3" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in BIND DNS Software Shipped With Solaris May Allow DNS Cache Poisoning</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022"/>
        <description>Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-03T13:51:32.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-05-05T11:43:54.594-04:00">DRAFT</status_change>
            <status_change date="2010-05-24T04:00:04.610-04:00">INTERIM</status_change>
            <status_change date="2010-06-14T04:00:54.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 273169">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 112837-21 or later installed" test_ref="oval:org.mitre.oval:tst:10994"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273169">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 119783-14 or later installed" test_ref="oval:org.mitre.oval:tst:11625"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 273169">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114265-20 or later installed" test_ref="oval:org.mitre.oval:tst:11199"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273169">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 119784-14 or later installed" test_ref="oval:org.mitre.oval:tst:11385"/>
          </criteria>
        </criteria>
        <criterion comment="in.named running" test_ref="oval:org.mitre.oval:tst:2624"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7450" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1321"/>
        <description>The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:35:23.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:55.609-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:50.450-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:54.608-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:06.182-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:55.641-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:29.657-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:34.917-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:40.030-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:34.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41168 is installed" test_ref="oval:org.mitre.oval:tst:20503"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41167 is installed" test_ref="oval:org.mitre.oval:tst:21355"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41166 is installed" test_ref="oval:org.mitre.oval:tst:21374"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21255"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20686"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21334"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21081"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20956"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21369"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21120"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21060"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21383"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21317"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20710"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21337"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21431"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21330"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:744" version="1" class="vulnerability">
      <metadata>
        <title>Gaim DoS via Yahoo! Message</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1269"/>
        <description>Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="gaim RPM earlier than 1:1.3.1-0.el3" negate="false" test_ref="oval:org.mitre.oval:tst:2740"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/gaim is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:2739"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7439" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4143"/>
        <description>PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:49.825-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:50.155-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:54.281-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:03.993-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:55.544-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:23.763-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:34.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:36.739-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:34.548-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7430" version="3" class="vulnerability">
      <metadata>
        <title>A vulnerability in the way named(1M) handles recursive client queries may allow a remote unprivileged user to cause named(1M) to return NXDOMAIN (Non-Existent Domain) for Internet hosts thus causing a Denial of Service (DoS) for those hosts to end users</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097"/>
        <description>ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-03T13:51:32.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-05-05T11:43:55.135-04:00">DRAFT</status_change>
            <status_change date="2010-05-24T04:00:04.262-04:00">INTERIM</status_change>
            <status_change date="2010-06-14T04:00:52.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 275890">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 112837-21 or later installed" test_ref="oval:org.mitre.oval:tst:11747"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 275890">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 119783-15 or later installed" test_ref="oval:org.mitre.oval:tst:11052"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 275890">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114265-20 or later installed" test_ref="oval:org.mitre.oval:tst:11705"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 275890">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 119784-15 or later installed" test_ref="oval:org.mitre.oval:tst:11409"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="in.named running" test_ref="oval:org.mitre.oval:tst:2624"/>
          <criterion comment="Server is configured as DNSSEC-validating nameserver (trusted-keys is set in /etc/named.conf)" test_ref="oval:org.mitre.oval:tst:11254"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:742" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Improper Handling of Synthetic Events in Mozilla</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2260"/>
        <description>The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:74" version="3" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE dtspcd Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>dtspcd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0803"/>
        <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:14:00.836-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:14:25.949-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.778-04:00">ACCEPTED</status_change>
            <modified comment="Fixed incorrect user_id element value in process_state.  Incorrect value was 'root', updated to value of '0'." date="2010-09-02T15:11:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T15:13:54.018-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:35.977-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File dtspcd exists" negate="false" test_ref="oval:org.mitre.oval:tst:2983"/>
          <criterion comment="Patch 106934-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2974"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains dtspcd" negate="false" test_ref="oval:org.mitre.oval:tst:2981"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File dtspcd executable">
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2980"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2979"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2978"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7396" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3557" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3557"/>
        <description>The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:48.784-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:49.588-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:53.896-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:10.726-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:55.449-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:41.756-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:34.665-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:25.362-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:34.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7394" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3291" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3291"/>
        <description>The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:47.982-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:49.301-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:53.567-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:08.652-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:55.354-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:36.195-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:34.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:22.284-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:34.307-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:736" version="2" class="vulnerability">
      <metadata>
        <title>MIT Kerberos 5 Key Distribution Center Remote Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Kerberos</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1175"/>
        <description>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.863-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.079-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:02:00.285-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:04:28.310-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112536-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112537-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3424"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112237-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3567"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112238-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3898"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112390-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3640"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112240-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3497"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112908-20 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3389"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 115168-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3624"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120469-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3561"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120470-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:735" version="1" class="vulnerability">
      <metadata>
        <title>Apache Integer Overflow in pcre_compile.c</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7344" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2442"/>
        <description>The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:35:23.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:54.124-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:45.352-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:52.295-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:01.309-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:55.231-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:13.862-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:34.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:31.062-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:34.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41168 is installed" test_ref="oval:org.mitre.oval:tst:20503"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41167 is installed" test_ref="oval:org.mitre.oval:tst:21355"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41166 is installed" test_ref="oval:org.mitre.oval:tst:21374"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21255"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20686"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21334"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21081"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20956"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21369"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21120"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21060"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21383"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21317"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20710"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21337"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21431"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21330"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:73" version="2" class="vulnerability">
      <metadata>
        <title>Integer Overflow Vulnerabilities in Ethereal 0.9.11</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0357"/>
        <description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.945-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:729" version="5" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla DOM Node Spoofing</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2269"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11366 - Updated CPE reference, updated regular expression" date="2011-02-17T13:29:00.547-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-02-17T13:31:09.465-05:00">INTERIM</status_change>
            <status_change date="2011-03-07T04:00:15.121-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11366 - Corrected - right version for brlapi and brlapi-devel as specified by RHSA-2010:0181-5" date="2013-03-18T12:26:00.995-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-18T12:31:13.197-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:48.317-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:728" version="7" class="vulnerability">
      <metadata>
        <title>HP-UX 11 Perl rmtree Race Condition</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0448"/>
        <description>Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.495-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.663-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:48:00.580-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:49:04.605-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.449-04:00">ACCEPTED</status_change>
            <modified comment="Updated the datatype from 'string' to 'fileset_revision' to match Schematron rules." date="2010-09-02T11:23:00.789-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T11:41:03.259-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:35.508-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:16.053-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:54.839-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Perl 5.6 or 5.8 vulnerable on 11.00, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Perl version 5.6.0 is installed or 5.8.0 without revision G or later is installed" negate="false">
            <criterion comment="Perl 5.6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3419"/>
            <criterion comment="Perl 5.8.0 (revision F or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.00 or 11.11" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.11" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision C or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3226"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision E or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3635"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.3 vulnerable on 11.0, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.3,revision A is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3847"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7261" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX Running BIND, Remote Denial of Service (DoS), Unauthorized Disclosure of Information</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022"/>
        <description>Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:04:56.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:58.838-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:44.080-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:51.941-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:00.974-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:54.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
            <criterion comment="BindUpgrade.BIND2-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21376"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-INETD is installed" test_ref="oval:org.mitre.oval:tst:21277"/>
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21460"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:21294"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40339 is installed" test_ref="oval:org.mitre.oval:tst:21189"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.11.01.015" test_ref="oval:org.mitre.oval:tst:20542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:726" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX 11.00 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.288-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.492-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:52:00.826-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:53:23.849-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.287-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.157-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.290-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:726 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:50.414-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:45.820-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="Patch PHNE_33395 is installed" test_ref="oval:org.mitre.oval:tst:3393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7257" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813"/>
        <description>Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-04T14:16:08.000-05:00">
              <contributor organization="Hewlett-Packard">Aslesha Nargolkar</contributor>
            </submitted>
            <status_change date="2010-10-05T14:11:03.814-04:00">DRAFT</status_change>
            <status_change date="2010-10-25T04:00:25.959-04:00">INTERIM</status_change>
            <status_change date="2010-11-15T04:00:43.619-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:00.644-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:54.628-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:11.083-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:34.105-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:29.836-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:33.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02479 SSRT090212 rev.1">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11391"/>
            <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11048"/>
            <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11225"/>
            <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11197"/>
            <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11120"/>
            <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11346"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02479 SSRT090212 rev.1">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11548"/>
            <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11809"/>
            <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11334"/>
            <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11446"/>
            <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11049"/>
            <criterion comment="CIFS-CFSM.CFSM-KRN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11672"/>
            <criterion comment="CIFS-CFSM.CFSM-RUN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02479 SSRT090212 rev.1">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11548"/>
            <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11809"/>
            <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11334"/>
            <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11446"/>
            <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11049"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7256" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4018"/>
        <description>The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:49.336-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:43.312-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:51.623-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:00.517-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:54.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:10.834-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:33.943-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:29.628-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:33.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:724" version="4" class="vulnerability">
      <metadata>
        <title>MIT Kerberos 5 KRB5_AName_To_Localname Multiple Principal Name Buffer Overrun Vulnerabilities</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0523"/>
        <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.045-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.217-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:49:00.749-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:50:17.774-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.042-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:724 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:51.141-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:44.632-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software section">
          <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101512 criteria.">
            <criterion comment="Solaris 7 Installed" test_ref="oval:org.mitre.oval:tst:3576"/>
            <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion negate="true" comment="Patch 112536-05 or later installed" test_ref="oval:org.mitre.oval:tst:3544"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101512 criteria.">
            <criterion comment="Solaris 7 Installed" test_ref="oval:org.mitre.oval:tst:3576"/>
            <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion negate="true" comment="Patch 112537-05 or later installed" test_ref="oval:org.mitre.oval:tst:3498"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101512 criteria.">
            <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion negate="true" comment="Patch 112237-11 or later installed" test_ref="oval:org.mitre.oval:tst:3354"/>
            <criterion negate="true" comment="Patch 112390-09 or later installed" test_ref="oval:org.mitre.oval:tst:3509"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101512 criteria.">
            <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion negate="true" comment="Patch 112240-08 or later installed" test_ref="oval:org.mitre.oval:tst:3366"/>
            <criterion negate="true" comment="Patch 112238-10 or later installed" test_ref="oval:org.mitre.oval:tst:4043"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101512 criteria.">
            <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion negate="true" comment="Patch 112908-15 or later installed" test_ref="oval:org.mitre.oval:tst:3824"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101512 criteria.">
            <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion negate="true" comment="Patch 115168-05 or later installed" test_ref="oval:org.mitre.oval:tst:4066"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criteria operator="OR" comment="Target's configuration meets 101512 configuration criteria.">
            <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)">
              <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" test_ref="oval:org.mitre.oval:tst:3514"/>
              <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" test_ref="oval:org.mitre.oval:tst:3192"/>
              <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" test_ref="oval:org.mitre.oval:tst:3873"/>
              <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" test_ref="oval:org.mitre.oval:tst:3369"/>
            </criteria>
            <criteria operator="AND" comment="SEAM is not installed, but target is a kerberos client.">
              <criteria negate="true" operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)">
                <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" test_ref="oval:org.mitre.oval:tst:3514"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" test_ref="oval:org.mitre.oval:tst:3192"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" test_ref="oval:org.mitre.oval:tst:3873"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" test_ref="oval:org.mitre.oval:tst:3369"/>
              </criteria>
              <criterion comment="/etc/krb5/krb5.conf is configured as a kerberos client" test_ref="oval:org.mitre.oval:tst:3487"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7233" version="3" class="vulnerability">
      <metadata>
        <title>Sun Management Center Product Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0891"/>
        <description>Unspecified vulnerability in the Sun Management Center component in Oracle Sun Product Suite 3.6.1 and 4.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Solaris Container Manager.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-21T14:34:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-22T13:39:59.376-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:48.442-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:34.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 248666">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125833-05 or later installed" test_ref="oval:org.mitre.oval:tst:11416"/>
          <criterion comment="SUNWessrv 3.6.1 is installed" test_ref="oval:org.mitre.oval:tst:11331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 248666">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139613-01 or later installed" test_ref="oval:org.mitre.oval:tst:11194"/>
          <criterion comment="SUNWessrv 4.0 is installed" test_ref="oval:org.mitre.oval:tst:11341"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 248666">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143314-02 or later installed" test_ref="oval:org.mitre.oval:tst:11027"/>
          <criterion comment="SUNWessrv 4.0 is installed" test_ref="oval:org.mitre.oval:tst:11341"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:717" version="2" class="vulnerability">
      <metadata>
        <title>gftp Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gftp</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0372"/>
        <description>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-25T10:22:00.000-04:00" comment="modified upt-62 - Changed DATA operation to OR (to test for any exec bit set, not all).  Fixed typo in comment.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-01-25T07:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="gftp rpm is earlier than 1:2.0.14-4" negate="false" test_ref="oval:org.mitre.oval:tst:2394"/>
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="gftp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7131" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2443" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2443"/>
        <description>Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:35:23.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:54.660-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:40.960-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:50.727-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:06.422-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:54.222-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:30.072-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:33.792-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:40.280-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:33.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41168 is installed" test_ref="oval:org.mitre.oval:tst:20503"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41167 is installed" test_ref="oval:org.mitre.oval:tst:21355"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41166 is installed" test_ref="oval:org.mitre.oval:tst:21374"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21255"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20686"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21334"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21081"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20956"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21369"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21120"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21060"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21383"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21317"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20710"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21337"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21431"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21330"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:711" version="1" class="vulnerability">
      <metadata>
        <title>ImageMagick Buffer Overflow in ReadPNMImage()</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1275" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1275"/>
        <description>Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-28T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ImageMagick RPM earlier than 0:5.5.6-14" negate="false" test_ref="oval:org.mitre.oval:tst:2401"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7092" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary File Modification</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2902" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2902"/>
        <description>Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:43:28.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:44.281-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:39.974-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:50.181-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:12.262-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:54.137-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:47.228-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:33.689-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:27.369-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:33.480-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21400"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7085" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4142"/>
        <description>The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:49.584-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:39.694-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:49.830-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:10.581-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:54.043-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:41.349-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:33.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:25.192-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:33.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7050" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX running Software Distributor (sd), Local Privilege Increase, Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2712" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2712"/>
        <description>Unspecified vulnerability in Software Distributor (sd) in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:20:18.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:07:02.544-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:38.858-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:49.421-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:05.951-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:53.894-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:27.244-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:33.462-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:18.624-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:33.215-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02552">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SW-DIST.GZIP is installed" test_ref="oval:org.mitre.oval:tst:20882"/>
            <criterion comment="SW-DIST.GZIP2 is installed" test_ref="oval:org.mitre.oval:tst:21440"/>
            <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:21154"/>
            <criterion comment="SW-DIST.SD2-AGENT is installed" test_ref="oval:org.mitre.oval:tst:21351"/>
            <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:21306"/>
            <criterion comment="SW-DIST.SD2-CMDS is installed" test_ref="oval:org.mitre.oval:tst:21392"/>
            <criterion comment="SW-DIST.SD-EXAMPLES is installed" test_ref="oval:org.mitre.oval:tst:20660"/>
            <criterion comment="SW-DIST.SD-FAL is installed" test_ref="oval:org.mitre.oval:tst:21229"/>
            <criterion comment="SW-DIST.SD-PROVIDER is installed" test_ref="oval:org.mitre.oval:tst:21244"/>
            <criterion comment="SW-DIST.SD2-PROVIDER is installed" test_ref="oval:org.mitre.oval:tst:21422"/>
          </criteria>
          <criteria negate="true" operator="OR" comment="Patch PHCO_41201 and PHCO_41202 are installed">
            <criterion comment="Patch PHCO_41201 is installed" test_ref="oval:org.mitre.oval:tst:20517"/>
            <criterion comment="Patch PHCO_41202 is installed" test_ref="oval:org.mitre.oval:tst:21010"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02552">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SW-DIST.GZIP is installed" test_ref="oval:org.mitre.oval:tst:20882"/>
            <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:21154"/>
            <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:21306"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_41200 is installed" test_ref="oval:org.mitre.oval:tst:21201"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7047" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3293" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3293"/>
        <description>Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:48.537-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:38.543-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:49.107-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:05.010-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:53.792-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:24.867-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:33.358-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:17.505-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:33.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7033" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary File Modification</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3548" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3548"/>
        <description>The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:43:28.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:44.460-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:38.321-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:48.824-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:03.039-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:53.720-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:19.328-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:33.260-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:15.227-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:32.987-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21400"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7023" version="3" class="vulnerability">
      <metadata>
        <title>Solaris and OpenSolaris products Trusted Extensions component vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0882"/>
        <description>Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_134 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Trusted Extensions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-21T14:34:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-22T13:39:58.737-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:37.659-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:22.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 263689">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criteria operator="OR">
              <criterion negate="true" comment="Patch 119906-15 or later installed" test_ref="oval:org.mitre.oval:tst:11348"/>
              <criterion negate="true" comment="Patch 122212-36 or later installed" test_ref="oval:org.mitre.oval:tst:11584"/>
              <criterion negate="true" comment="Patch 120460-16 or later installed" test_ref="oval:org.mitre.oval:tst:11336"/>
              <criterion negate="true" comment="Patch 120094-25 or later installed" test_ref="oval:org.mitre.oval:tst:11607"/>
              <criterion negate="true" comment="Patch 122470-03 or later installed" test_ref="oval:org.mitre.oval:tst:11633"/>
              <criterion negate="true" comment="Patch 125533-15 or later installed" test_ref="oval:org.mitre.oval:tst:11661"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 263689">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criteria>
              <criterion negate="true" comment="Patch 122471-03 or later installed" test_ref="oval:org.mitre.oval:tst:11394"/>
              <criterion negate="true" comment="Patch 125534-15 or later installed" test_ref="oval:org.mitre.oval:tst:10950"/>
              <criterion negate="true" comment="Patch 119907-15 or later installed" test_ref="oval:org.mitre.oval:tst:11613"/>
              <criterion negate="true" comment="Patch 122213-36 or later installed" test_ref="oval:org.mitre.oval:tst:11317"/>
              <criterion negate="true" comment="Patch 120461-16 or later installed" test_ref="oval:org.mitre.oval:tst:11724"/>
              <criterion negate="true" comment="Patch 120095-25 or later installed" test_ref="oval:org.mitre.oval:tst:11890"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="System is configured to use Solaris Trusted Extensions (labeld service is online)" test_ref="oval:org.mitre.oval:tst:11134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:702" version="3" class="vulnerability">
      <metadata>
        <title>Solaris Privilege Escalation/DoS Vulnerability (6293270)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0190"/>
        <description>Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-12T11:25:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:702 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:50.977-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:43.069-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102066 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Contributing factors for Solaris 9, Sun Alert ID 102066 criteria.">
            <criterion comment="Patch 112234-11 is installed" test_ref="oval:org.mitre.oval:tst:2413"/>
            <criterion comment="Patch 112234-12 is installed" test_ref="oval:org.mitre.oval:tst:2412"/>
            <criterion comment="Patch 117172-16 or later installed" test_ref="oval:org.mitre.oval:tst:2411"/>
          </criteria>
          <criterion negate="true" comment="Patch 118559-19 or later installed" test_ref="oval:org.mitre.oval:tst:2410"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion negate="true" comment="Patch 118844-24 or later installed" test_ref="oval:org.mitre.oval:tst:2409"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7017" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary File Modification</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2693"/>
        <description>Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:43:28.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:44.009-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:38.095-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:48.590-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:04.705-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:53.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:25.585-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:33.172-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:37.686-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:32.798-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21400"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:70" version="3" class="vulnerability">
      <metadata>
        <title>Solaris 8 CDE dtspcd Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>dtspcd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0803"/>
        <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-23T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:14:00.836-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:14:26.106-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.399-04:00">ACCEPTED</status_change>
            <modified comment="Fixed incorrect user_id element value in process_state.  Incorrect value was 'root', updated to value of '0'." date="2010-09-02T15:11:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T15:13:54.164-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:35.161-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File dtspcd exists" negate="false" test_ref="oval:org.mitre.oval:tst:2983"/>
          <criterion comment="Patch 108949-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2982"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains dtspcd" negate="false" test_ref="oval:org.mitre.oval:tst:2981"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File dtspcd executable">
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2980"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2979"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2978"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 kcms_configure Command-Line Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>kcms_configure</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0594"/>
        <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File kcms_configure exists" negate="false" test_ref="oval:org.mitre.oval:tst:3144"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File kcms_configure executable and SUID or SGID">
            <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3143"/>
            <criteria operator="OR" comment="File kcms_configure executable and SUID or SGID">
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3142"/>
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3141"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6959" version="3" class="vulnerability">
      <metadata>
        <title>Solaris and OpenSolaris Products /dev/ucode Component Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0453" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0453"/>
        <description>The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-21T14:34:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-22T13:39:57.116-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:34.611-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:19.634-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
        <criterion comment="Patch 127128-11 installed" test_ref="oval:org.mitre.oval:tst:11295"/>
        <criterion negate="true" comment="Patch 143913-01 or later installed" test_ref="oval:org.mitre.oval:tst:11675"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6914" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Directory Server and Red Hat Directory Server for HP-UX, Local Disclosure of Information, Privilege Escalation</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3282"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T10:49:54.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:07:06.649-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:36.166-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:47.533-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:10.493-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:53.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:41.056-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:32.992-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:24.993-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:32.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02587">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="HpuxDirSvr.ADMSVR-RUN version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:21397"/>
            <criterion comment="HpuxDirSvr.ADMSVR-SHARED version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20728"/>
            <criterion comment="HpuxDirSvr.CORE-RUN version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:21489"/>
            <criterion comment="HpuxDirSvr.GUI-HELP version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20905"/>
            <criterion comment="HpuxDirSvr.GUI-RUN version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:21453"/>
            <criterion comment="HpuxDirSvr.GUI-SHARED version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20988"/>
            <criterion comment="HpuxDirSvr.SLAPD-DEVEL version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20742"/>
            <criterion comment="HpuxDirSvr.SLAPD-RUN version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:21522"/>
            <criterion comment="HpuxDirSvr.SLAPD-SHARED version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20800"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02587">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RedHatDirSvr.ADMSVR-RUN version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21325"/>
            <criterion comment="RedHatDirSvr.ADMSVR-SHARED version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21413"/>
            <criterion comment="RedHatDirSvr.CORE-RUN version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21457"/>
            <criterion comment="RedHatDirSvr.GUI-HELP version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21498"/>
            <criterion comment="RedHatDirSvr.GUI-RUN version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21349"/>
            <criterion comment="RedHatDirSvr.GUI-SHARED version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21196"/>
            <criterion comment="RedHatDirSvr.SLAPD-DEVEL version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21502"/>
            <criterion comment="RedHatDirSvr.SLAPD-RUN version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:20565"/>
            <criterion comment="RedHatDirSvr.SLAPD-SHARED version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21333"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:69" version="2" class="vulnerability">
      <metadata>
        <title>Off-by-one Vulnerabilities in Ethereal 0.9.11</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0356"/>
        <description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:47.572-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6892" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX Running sendmail, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2261"/>
        <description>Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-01T14:30:46.000-05:00">
              <contributor organization="Hewlett-Packard">Aslesha</contributor>
            </submitted>
            <status_change date="2010-10-05T14:11:00.152-04:00">DRAFT</status_change>
            <status_change date="2010-10-25T04:00:21.132-04:00">INTERIM</status_change>
            <status_change date="2010-11-15T04:00:35.522-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:12.673-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:53.308-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495 SSRT090151 rev.2">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11578"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:11885"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40388 is installed" test_ref="oval:org.mitre.oval:tst:11506"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495 SSRT090151 rev.2">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SMAIL-811.INETSVCS-SMAIL version is less than SMAIL-813" test_ref="oval:org.mitre.oval:tst:11251"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495 SSRT090151 rev.2">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11578"/>
          <criterion negate="true" comment="Patch PHNE_40393 is installed" test_ref="oval:org.mitre.oval:tst:11879"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:688" version="8" class="vulnerability">
      <metadata>
        <title>HP-UX 11.23 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.358-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.763-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:53:00.978-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:53:50.998-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:24.308-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.069-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.145-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:688 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:24.592-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:41.079-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:06.502-05:00">INTERIM</status_change>
            <status_change date="2014-03-10T04:00:51.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="Patch PHNE_32606 is installed" test_ref="oval:org.mitre.oval:tst:3439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6845" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris Trusted Extensions may Prevent XScreenSaver (xscreensaver(1)) From Running</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3851" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3851"/>
        <description>Trusted Extensions in Sun Solaris 10 interferes with the operation of the xscreensaver-demo command for the XScreenSaver application, which makes it easier for physically proximate attackers to access an unattended workstation for which the intended screen locking did not occur, related to the "restart daemon."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-17T14:02:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-17T17:21:51.728-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:55.593-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:26.233-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 270809">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion comment="Patch 125533-14 or later installed" test_ref="oval:org.mitre.oval:tst:11265"/>
            <criterion negate="true" comment="Patch 120094-28 or later installed" test_ref="oval:org.mitre.oval:tst:11162"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 270809">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion comment="Patch 125534-14 or later installed" test_ref="oval:org.mitre.oval:tst:11107"/>
            <criterion negate="true" comment="Patch 120095-28 or later installed" test_ref="oval:org.mitre.oval:tst:10350"/>
          </criteria>
        </criteria>
        <criterion comment="System is configured to use Solaris Trusted Extensions (labeld service is online)" test_ref="oval:org.mitre.oval:tst:11134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6822" version="3" class="vulnerability">
      <metadata>
        <title>IBM AIX "qosmod" Command Buffer Overflow Privilege Escalation Issue</title>
        <affected family="unix">
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0960" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0960"/>
        <description>Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-08T13:58:40.680-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:28.681-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:13.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ71870 are installed" test_ref="oval:org.mitre.oval:tst:11721"/>
          <criterion comment="Fileset bos.net.tcp.server is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:11419"/>
          <criterion comment="Fileset bos.net.tcp.server is less than or equal 6.1.1.7" test_ref="oval:org.mitre.oval:tst:11788"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ71627 are installed" test_ref="oval:org.mitre.oval:tst:11115"/>
          <criterion comment="Fileset bos.net.tcp.server is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:11767"/>
          <criterion comment="Fileset bos.net.tcp.server is less than or equal 6.1.2.4" test_ref="oval:org.mitre.oval:tst:11281"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-03 is installed" definition_ref="oval:org.mitre.oval:def:6736"/>
          <criterion negate="true" comment="All filesets for APAR IZ71555 are installed" test_ref="oval:org.mitre.oval:tst:11264"/>
          <criterion comment="Fileset bos.net.tcp.server is greater than or equal 6.1.3.0" test_ref="oval:org.mitre.oval:tst:11131"/>
          <criterion comment="Fileset bos.net.tcp.server is less than or equal 6.1.3.2" test_ref="oval:org.mitre.oval:tst:11491"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-04 is installed" definition_ref="oval:org.mitre.oval:def:7373"/>
          <criterion negate="true" comment="All filesets for APAR IZ68231 are installed" test_ref="oval:org.mitre.oval:tst:11659"/>
          <criterion comment="Fileset bos.net.tcp.server is greater than or equal 6.1.4.0" test_ref="oval:org.mitre.oval:tst:11356"/>
          <criterion comment="Fileset bos.net.tcp.server is less than or equal 6.1.4.1" test_ref="oval:org.mitre.oval:tst:11880"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6815" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX Running BIND, Remote Denial of Service (DoS), Unauthorized Disclosure of Information</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0290" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0290"/>
        <description>Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:04:56.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:59.165-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:33.753-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:46.617-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:06.115-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:53.193-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
            <criterion comment="BindUpgrade.BIND2-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21376"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-INETD is installed" test_ref="oval:org.mitre.oval:tst:21277"/>
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21460"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:21294"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40339 is installed" test_ref="oval:org.mitre.oval:tst:21189"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.11.01.015" test_ref="oval:org.mitre.oval:tst:20542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:68" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 7 admintool Local Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0089"/>
        <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:25:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:34.775-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1726, which had been badly mangled during conversion from OVAL 4.2 to 5.0.  Operation set to pattern match on path, and terminal regexp anchor moved from filename to path." date="2007-01-22T16:24:00.728-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:26:00.857-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:52.685-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
          <criterion comment="Patch 108721-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2986"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:676" version="1" class="vulnerability">
      <metadata>
        <title>PostgreSQL Character Conversion Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>postgresql</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1409" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1409"/>
        <description>PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-27T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="rh-postgresql-server is earlier than 0:7.3.10-1" negate="false" test_ref="oval:org.mitre.oval:tst:2433"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="postmaster (the PostgreSQL master daemon) is running" negate="false" test_ref="oval:org.mitre.oval:tst:2432"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:67" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8 admintool Local Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0089"/>
        <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:24:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:34.346-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1726, which had been badly mangled during conversion from OVAL 4.2 to 5.0.  Operation set to pattern match on path, and terminal regexp anchor moved from filename to path." date="2007-01-22T16:24:00.728-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:26:01.442-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:52.089-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
          <criterion comment="Patch 110453-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2987"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:667" version="4" class="vulnerability">
      <metadata>
        <title>ypserv NIS Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>ypserv</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0251" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0251"/>
        <description>ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.920-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.014-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.450-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:59:09.017-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:34.808-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ypserv version is less than 2.8-0.9E" negate="false" test_ref="oval:org.mitre.oval:tst:2451"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ypserv is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6667" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4017"/>
        <description>PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:49.102-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:30.004-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:45.405-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:05.152-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:52.911-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:25.102-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:32.773-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:17.593-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:32.498-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6665" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX Running BIND, Remote Denial of Service (DoS), Unauthorized Disclosure of Information</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0382"/>
        <description>ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819.  NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:04:56.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:59.379-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:29.725-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:45.113-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:04.660-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:52.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
            <criterion comment="BindUpgrade.BIND2-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21376"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-INETD is installed" test_ref="oval:org.mitre.oval:tst:21277"/>
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21460"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:21294"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40339 is installed" test_ref="oval:org.mitre.oval:tst:21189"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.11.01.015" test_ref="oval:org.mitre.oval:tst:20542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6655" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2687" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2687"/>
        <description>The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:47.660-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:29.397-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:44.747-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:06.968-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:52.573-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:30.731-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:32.647-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:20.159-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:32.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6644" version="1" class="vulnerability">
      <metadata>
        <title>A Regression in the Solaris 10 Gnome-XScreenSaver (see xscreensaver(1)) may Allow Pop-up Windows to Appear through XScreenSaver when the Accessibility Feature is On</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3746" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3746"/>
        <description>XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276 and CVE-2009-2711.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-17T14:02:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-17T17:21:50.768-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:54.722-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:25.444-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 268288">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR">
            <criterion comment="Patch 120094-27 installed" test_ref="oval:org.mitre.oval:tst:11280"/>
            <criterion comment="Patch 120094-28 installed" test_ref="oval:org.mitre.oval:tst:11303"/>
          </criteria>
          <criterion negate="true" comment="Patch 120094-29 or later installed" test_ref="oval:org.mitre.oval:tst:11098"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 268288">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR">
            <criterion comment="Patch 120095-27 installed" test_ref="oval:org.mitre.oval:tst:11187"/>
            <criterion comment="Patch 120095-28 installed" test_ref="oval:org.mitre.oval:tst:10782"/>
          </criteria>
          <criterion negate="true" comment="Patch 120095-29 or later installed" test_ref="oval:org.mitre.oval:tst:11260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:664" version="2" class="vulnerability">
      <metadata>
        <title>Code Execution Vulnerability in XPDF PDF Viewer</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>xpdf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0434" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0434"/>
        <description>Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.685-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.816-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="xpdf version is less than 2.0.1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2455"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="xpdf is executable">
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2454"/>
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2453"/>
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2452"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6628" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0580" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0580"/>
        <description>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-13T16:45:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-09T17:16:22.921-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:39.735-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:12.924-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:10.952-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:52.469-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:42.556-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:32.315-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:25.638-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:32.183-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11215"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:662" version="4" class="vulnerability">
      <metadata>
        <title>lpsched Local System Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0227"/>
        <description>Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-16T12:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1394 to more correctly look for subdirectories under /etc/lp/printers." date="2007-01-22T16:00:00.391-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:01:01.488-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:51.556-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:662 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:54.814-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:39.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion negate="true" comment="Patch 109320-17 or later installed" test_ref="oval:org.mitre.oval:tst:2464"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion negate="true" comment="Patch 109321-17 or later installed" test_ref="oval:org.mitre.oval:tst:2462"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion negate="true" comment="Patch 113329-16 or later installed" test_ref="oval:org.mitre.oval:tst:2461"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion negate="true" comment="Patch 114980-17 or later installed" test_ref="oval:org.mitre.oval:tst:2460"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (sparc) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion negate="true" comment="Patch 120467-03 or later installed" test_ref="oval:org.mitre.oval:tst:2458"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion negate="true" comment="Patch 120468-03 or later installed" test_ref="oval:org.mitre.oval:tst:2457"/>
        </criteria>
        <criterion comment="Target is configured as a print server" test_ref="oval:org.mitre.oval:tst:2456"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:657" version="4" class="vulnerability">
      <metadata>
        <title>xinitd Memory Leak Invites Denial of Service Attack</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>xinetd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0211"/>
        <description>Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-17T12:00:00.000-04:00" comment="Changed tested epoch in xinetd test rvt-253 to 2, based on testing.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:40.150-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.517-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.551-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:58:51.127-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:34.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="xinetd version is less than 2:2.3.11-1.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2467"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="xinetd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2466"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6564" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0781"/>
        <description>Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-13T16:45:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-09T17:16:23.143-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:37.592-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:10.401-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:05.269-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:52.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:25.325-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:32.210-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:17.722-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:32.027-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11215"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6563" version="1" class="vulnerability">
      <metadata>
        <title>A security vulnerability in Solaris Sockets Direct Protocol (SDP) driver (sdp(7D)) may allow a local or remote unprivileged user to exhaust all kernel memory</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3899" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3899"/>
        <description>Memory leak in the Sockets Direct Protocol (SDP) driver in Sun Solaris 10, and OpenSolaris snv_57 through snv_94, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-17T14:02:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-17T17:21:51.272-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:53.927-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:25.197-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 264730">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 127127-11 or later installed" test_ref="oval:org.mitre.oval:tst:11269"/>
          <criterion negate="true" comment="Patch 141444-09 or later installed" test_ref="oval:org.mitre.oval:tst:10510"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 264730">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 127128-11 or later installed" test_ref="oval:org.mitre.oval:tst:11157"/>
          <criterion negate="true" comment="Patch 141445-09 or later installed" test_ref="oval:org.mitre.oval:tst:11189"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:651" version="8" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 or 11.23 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.103-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.450-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:43:00.954-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:44:10.985-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:23.230-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:651 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:15.190-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:39.616-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:13.099-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:52.274-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:65" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 kcms_configure Command-Line Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>kcms_configure</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0594"/>
        <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File kcms_configure exists" negate="false" test_ref="oval:org.mitre.oval:tst:3144"/>
          <criterion comment="Patch 107337-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2989"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File kcms_configure executable and SUID or SGID">
            <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3143"/>
            <criteria operator="OR" comment="File kcms_configure executable and SUID or SGID">
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3142"/>
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3141"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6480" version="1" class="vulnerability">
      <metadata>
        <title>A Security Weakness in Solaris Trusted Extensions May Facilitate Privilege Escalation</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3839"/>
        <description>Unspecified vulnerability in the Solaris Trusted Extensions Policy configuration in Sun Solaris 10, and OpenSolaris snv_37 through snv_125, might allow remote attackers to execute arbitrary code by leveraging access to the X server.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-17T14:02:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-17T17:21:52.077-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:49.466-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:19.287-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 270969">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 126363-08 or later installed" test_ref="oval:org.mitre.oval:tst:11099"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 270969">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 126364-08 or later installed" test_ref="oval:org.mitre.oval:tst:11324"/>
          </criteria>
        </criteria>
        <criterion comment="System is configured to use Solaris Trusted Extensions (labeld service is online)" test_ref="oval:org.mitre.oval:tst:11134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:648" version="5" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:50.907-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.972-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.030-04:00">ACCEPTED</status_change>
            <modified comment="Updated the datatype from 'string' to 'fileset_revision' to match Schematron rules." date="2010-09-02T11:23:00.280-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T11:46:36.089-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:34.087-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2472"/>
        <criteria operator="OR" comment="Either PHNE_30983 or PHNE_31732 is installed" negate="true">
          <criterion comment="Patch PHNE_30983 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2471"/>
          <criterion comment="Patch PHNE_31732 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:647" version="1" class="vulnerability">
      <metadata>
        <title>mikmod Long Filename Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mikmod</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0427"/>
        <description>Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="mikmod RPM prior to 0:3.1.6-22.EL3" negate="false" test_ref="oval:org.mitre.oval:tst:2474"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mikmod is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:2473"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6450" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0783"/>
        <description>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-13T16:45:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-09T17:16:23.316-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:34.783-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:09.152-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:05.330-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:52.180-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:25.544-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:32.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:17.802-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:31.847-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11215"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6445" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5515" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5515"/>
        <description>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-13T16:45:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-09T17:16:22.453-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:34.493-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:08.845-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:33.953-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:52.087-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:34:42.026-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:32.012-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:54.001-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:31.730-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11215"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:642" version="3" class="vulnerability">
      <metadata>
        <title>HP-Samba DACL Remote Integer Overflow Vulnerability (CIFS A.02)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154"/>
        <description>Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-13T02:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Updated the datatype from 'string' to 'fileset_revision' to match Schematron rules." date="2010-09-02T11:23:00.413-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T11:44:54.135-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:33.713-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Any of the CIFS components has a version equal to A.02.01">
          <criterion comment="CIFS-Server.CIFS-RUN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2481"/>
          <criterion comment="CIFS-Server.CIFS-UTIL with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2480"/>
          <criterion comment="CIFS-Server.CIFS-ADMIN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2479"/>
          <criterion comment="CIFS-Server.CIFS-LIB with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2478"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6402" version="1" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in muxatmd.</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1355"/>
        <description>Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-01T16:26:02-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-06T11:03:47.441-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:11.640-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:12.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 5.2 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5.2 is installed" definition_ref="oval:org.mitre.oval:def:5189"/>
          <criterion negate="true" comment="All filesets for APAR IZ48495 are installed" test_ref="oval:org.mitre.oval:tst:10554"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is greater than or equal 5.2.0.51" test_ref="oval:org.mitre.oval:tst:10505"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is less than or equal 5.2.0.97" test_ref="oval:org.mitre.oval:tst:10456"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-00 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-00 is installed" definition_ref="oval:org.mitre.oval:def:6195"/>
          <criterion negate="true" comment="All filesets for APAR IZ48496 are installed" test_ref="oval:org.mitre.oval:tst:10342"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is greater than or equal 5.3.0.60" test_ref="oval:org.mitre.oval:tst:9636"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is less than or equal 5.3.0.63" test_ref="oval:org.mitre.oval:tst:10287"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-01 through 5300-06 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-01 through 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:5973"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is installed" test_ref="oval:org.mitre.oval:tst:10145"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ48499 are installed" test_ref="oval:org.mitre.oval:tst:10228"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10182"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is less than or equal 5.3.7.2" test_ref="oval:org.mitre.oval:tst:10255"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ48500 are installed" test_ref="oval:org.mitre.oval:tst:10225"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is equal to 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10533"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ48501 are installed" test_ref="oval:org.mitre.oval:tst:10515"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is equal to 5.3.9.0" test_ref="oval:org.mitre.oval:tst:10508"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ48502 are installed" test_ref="oval:org.mitre.oval:tst:10140"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:9677"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is less than or equal 6.1.0.1" test_ref="oval:org.mitre.oval:tst:10201"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ48561 are installed" test_ref="oval:org.mitre.oval:tst:10449"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is equal to 6.1.1.0" test_ref="oval:org.mitre.oval:tst:9925"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ48562 are installed" test_ref="oval:org.mitre.oval:tst:10486"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is equal to 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10294"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6392" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris pollwakeup(9F) May Allow an Unprivileged User to Panic the System</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2952" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2952"/>
        <description>Unspecified vulnerability in the pollwakeup function in Sun Solaris 10, and OpenSolaris before snv_51, allows local users to cause a denial of service (panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-25T16:38:09.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-26T08:16:49.443-04:00">DRAFT</status_change>
            <status_change date="2009-09-14T04:00:11.965-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:06.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 265248">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-09 or later installed" test_ref="oval:org.mitre.oval:tst:10377"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 265248">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-09 or later installed" test_ref="oval:org.mitre.oval:tst:10060"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6387" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0847"/>
        <description>The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:14.604-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.778-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:08.459-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:09.872-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:51.937-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:39.695-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:31.885-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:24.305-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:31.586-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9858"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10546"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9864"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10283"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10041"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10495"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10331"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10556"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10551"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10305"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10501"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10039"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10539"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10262"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:637" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox and Mozilla Framed Site Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1937" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1937"/>
        <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6366" version="1" class="vulnerability">
      <metadata>
        <title>AIX NFSv4 nfs_portmon vulnerability</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3517" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3517"/>
        <description>nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-09T14:55:01.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-10-22T17:35:31.459-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:50.517-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:35.147-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ50496 are installed" test_ref="oval:org.mitre.oval:tst:10813"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10610"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.7.8" test_ref="oval:org.mitre.oval:tst:10136"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ50444 are installed" test_ref="oval:org.mitre.oval:tst:10995"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:11086"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.8.6" test_ref="oval:org.mitre.oval:tst:10144"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ50399 are installed" test_ref="oval:org.mitre.oval:tst:11020"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:11094"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:11066"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ49278 are installed" test_ref="oval:org.mitre.oval:tst:10801"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:11068"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.0.8" test_ref="oval:org.mitre.oval:tst:10960"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ49096 are installed" test_ref="oval:org.mitre.oval:tst:10630"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:11058"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.1.4" test_ref="oval:org.mitre.oval:tst:10606"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ49024 are installed" test_ref="oval:org.mitre.oval:tst:10846"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10684"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.2.3" test_ref="oval:org.mitre.oval:tst:10664"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6361" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris IP Filter (ipf(5)) May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2487"/>
        <description>Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-12T12:29:13.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T18:16:43.070-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.479-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 260951">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criteria operator="OR">
              <criterion comment="Patch 125014-02 or later installed" test_ref="oval:org.mitre.oval:tst:10532"/>
              <criterion comment="Patch 120011-14 or later installed" test_ref="oval:org.mitre.oval:tst:10461"/>
            </criteria>
            <criterion negate="true" comment="Patch 141020-01 or later installed" test_ref="oval:org.mitre.oval:tst:10397"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 260951">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criteria>
              <criterion comment="Patch 125015-02 or later installed" test_ref="oval:org.mitre.oval:tst:10569"/>
              <criterion comment="Patch 120012-14 or later installed" test_ref="oval:org.mitre.oval:tst:10366"/>
            </criteria>
            <criterion negate="true" comment="Patch 141021-01 or later installed" test_ref="oval:org.mitre.oval:tst:10459"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="ipfilter(5) is running" test_ref="oval:org.mitre.oval:tst:10149"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6353" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the SNMP daemon (snmpd(1M)) May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4309"/>
        <description>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-10T11:34:43.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-09-10T19:37:14.283-04:00">DRAFT</status_change>
            <status_change date="2009-09-28T04:00:25.685-04:00">INTERIM</status_change>
            <status_change date="2009-10-19T04:00:16.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 262908">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 120272-25 or later installed" test_ref="oval:org.mitre.oval:tst:10802"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 262908">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 120273-27 or later installed" test_ref="oval:org.mitre.oval:tst:10754"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWsmagt is installed" test_ref="oval:org.mitre.oval:tst:10650"/>
        <criterion comment="sma service is enabled" test_ref="oval:org.mitre.oval:tst:10248"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6352" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running VERITAS File System (VRTSvxfs) or VERITAS Oracle Disk Manager (VRTSodm), Local Escalation of Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0207"/>
        <description>Unspecified vulnerability in HP-UX B.11.11 running VERITAS Oracle Disk Manager (VRTSodm) 3.5, B.11.23 running VRTSodm 4.1 or VERITAS File System (VRTSvxfs) 4.1, B.11.23 running VRTSodm 5.0 or VRTSvxfs 5.0, and B.11.31 running VRTSodm 5.0 allows local users to gain root privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-09T14:52:58.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-15T20:20:07.237-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:45.505-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:15.597-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:04.472-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:51.775-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:23.585-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:31.697-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:16.890-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:31.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02409">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="VRTSvxfs.VXFS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11292"/>
          <criterion negate="true" comment="Patch PHCO_39124 is installed" test_ref="oval:org.mitre.oval:tst:11283"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02409">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="VRTSvxfs or VRTSodm is vulnerable">
            <criteria operator="AND" comment="VRTSvxfs 4.1 or 5.0 is vulnerable">
              <criteria operator="OR" comment="VRTSvxfs 4.1 or 5.0 is installed">
                <criterion comment="VRTSvxfs.VXFS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11292"/>
                <criterion comment="VRTSvxfs.VXFS-RUN-PALIB is installed" test_ref="oval:org.mitre.oval:tst:11141"/>
                <criterion comment="VRTSvxfs.VXFS-PRG is installed" test_ref="oval:org.mitre.oval:tst:10996"/>
              </criteria>
              <criteria operator="OR" comment="PHCO_39027 not installed for 4.1, or patches PHCO_39103 and PHCO_39104 not installed for 5.0">
                <criterion negate="true" comment="Patch PHCO_39027 is installed" test_ref="oval:org.mitre.oval:tst:11186"/>
                <criteria negate="true" operator="AND">
                  <criterion comment="Patch PHCO_39103 is installed" test_ref="oval:org.mitre.oval:tst:10811"/>
                  <criterion comment="Patch PHCO_39104 is installed" test_ref="oval:org.mitre.oval:tst:11183"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="VRTSodm 4.1 or 5.0 is vulnerable">
              <criteria operator="OR" comment="VRTSodm 4.1 or 5.0 is installed">
                <criterion comment="VRTSodm.ODM-KRN is installed" test_ref="oval:org.mitre.oval:tst:11042"/>
                <criterion comment="VRTSodm.ODM-RUN is installed" test_ref="oval:org.mitre.oval:tst:11174"/>
                <criterion comment="VRTSodm.ODM-MAN is installed" test_ref="oval:org.mitre.oval:tst:10401"/>
              </criteria>
              <criteria operator="OR" comment="PHKL_39029 not installed for 4.1, or PHKL_38795 not installed for 5.0">
                <criterion negate="true" comment="Patch PHKL_39029 is installed" test_ref="oval:org.mitre.oval:tst:11218"/>
                <criterion negate="true" comment="Patch PHKL_38795 is installed" test_ref="oval:org.mitre.oval:tst:10890"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02409">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="VRTSvxfs or VRTSodm is vulnerable">
            <criteria operator="AND" comment="VRTSdom 5.0 is vulnerable">
              <criteria operator="OR">
                <criterion comment="VRTSodm.ODM-KRN is installed" test_ref="oval:org.mitre.oval:tst:11042"/>
                <criterion comment="VRTSodm.ODM-RUN is installed" test_ref="oval:org.mitre.oval:tst:11174"/>
                <criterion comment="VRTSodm.ODM-MAN is installed" test_ref="oval:org.mitre.oval:tst:10401"/>
              </criteria>
              <criterion comment="Patch PHKL_39130 is installed" test_ref="oval:org.mitre.oval:tst:11083"/>
            </criteria>
            <criteria operator="AND" comment="VRTSvxfs 5.0 is vulnerable">
              <criterion comment="VRTSvxfs.VXFS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11292"/>
              <criteria negate="true" operator="AND" comment="Patch PHCO_38913 and PHCO_39132 are installed">
                <criterion comment="Patch PHCO_38913 is installed" test_ref="oval:org.mitre.oval:tst:11118"/>
                <criterion comment="Patch PHCO_39132 is installed" test_ref="oval:org.mitre.oval:tst:10878"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6349" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris SCTP Packet Processing may Lead to a System Panic Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2486" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2486"/>
        <description>Unspecified vulnerability in the SCTP implementation in Sun Solaris 10, and OpenSolaris before snv_120, allows remote attackers to cause a denial of service (panic) via unspecified packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-12T12:29:13.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T18:16:42.390-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.243-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 253608">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-01 or later installed" test_ref="oval:org.mitre.oval:tst:10476"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 253608">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-01 or later installed" test_ref="oval:org.mitre.oval:tst:10522"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:634" version="4" class="vulnerability">
      <metadata>
        <title>vsftpd Fails to Integrate with TCP Wrappers</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>vsftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0135"/>
        <description>vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:23.164-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.322-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.109-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:58:30.699-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:33.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="vsftpd version is less than 1.1.3-8" negate="false" test_ref="oval:org.mitre.oval:tst:2487"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="vsftpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2486"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6331" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris rpc.nisd(1M) Daemon may Cause a Denial of Service (DoS) Condition to a NIS+ Server</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2029"/>
        <description>Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv_104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-23T12:21:57.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-06-30T10:48:13.719-04:00">DRAFT</status_change>
            <status_change date="2009-07-20T04:00:44.613-04:00">INTERIM</status_change>
            <status_change date="2009-08-10T04:00:08.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 and 9">
          <criteria operator="OR" comment="Solaris 8 and 9 software section">
            <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 256748">
              <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
              <criterion negate="true" comment="Patch 128624-09 or later installed" test_ref="oval:org.mitre.oval:tst:9596"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 256748">
              <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
              <criterion negate="true" comment="Patch 112960-65 or later installed" test_ref="oval:org.mitre.oval:tst:9856"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 256748">
              <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
              <criterion negate="true" comment="Patch 128625-09 or later installed" test_ref="oval:org.mitre.oval:tst:10082"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 256748">
              <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
              <criterion negate="true" comment="Patch 114242-50 or later installed" test_ref="oval:org.mitre.oval:tst:9784"/>
            </criteria>
          </criteria>
          <criterion comment="rpc.nisd service is running" test_ref="oval:org.mitre.oval:tst:10097"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10">
          <criteria operator="OR" comment="Solaris 10 software section">
            <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 256748">
              <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
              <criterion negate="true" comment="Patch 140917-01 or later installed" test_ref="oval:org.mitre.oval:tst:10226"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 256748">
              <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
              <criterion negate="true" comment="Patch 140918-01 or later installed" test_ref="oval:org.mitre.oval:tst:10054"/>
            </criteria>
          </criteria>
          <criterion comment="rpc.nisd service is running" test_ref="oval:org.mitre.oval:tst:10027"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6328" version="8" class="vulnerability">
      <metadata>
        <title>HP-UX Running Role-Based Access Control (RBAC), Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2682" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2682"/>
        <description>Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-07T11:33:53.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-10-09T14:07:00.581-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:05.422-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:19.006-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:43.698-05:00">INTERIM</status_change>
            <status_change date="2014-03-10T04:00:51.616-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:35:18.222-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:31.595-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:05.806-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:31.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02457">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RBAC.RBAC-CONF is installed" test_ref="oval:org.mitre.oval:tst:10651"/>
            <criterion comment="RBAC.RBAC-RUN is installed" test_ref="oval:org.mitre.oval:tst:10540"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_40131 is installed" test_ref="oval:org.mitre.oval:tst:10732"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02457">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RBAC.RBAC-CONF version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:9940"/>
            <criterion comment="RBAC.RBAC-RUN version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:10583"/>
            <criterion comment="RBAC.RBAC-WEB version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:10906"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6318" version="1" class="vulnerability">
      <metadata>
        <title>AIX NFSv4 Kerberos vulnerability</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3516"/>
        <description>gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-09T14:55:01.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-10-22T17:35:30.977-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:47.817-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:32.911-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ50496 are installed" test_ref="oval:org.mitre.oval:tst:10813"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10610"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.7.8" test_ref="oval:org.mitre.oval:tst:10136"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ50444 are installed" test_ref="oval:org.mitre.oval:tst:10995"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:11086"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.8.6" test_ref="oval:org.mitre.oval:tst:10144"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ50399 are installed" test_ref="oval:org.mitre.oval:tst:11020"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:11094"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:11066"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ49278 are installed" test_ref="oval:org.mitre.oval:tst:10801"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:11068"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.0.8" test_ref="oval:org.mitre.oval:tst:10960"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ49096 are installed" test_ref="oval:org.mitre.oval:tst:10630"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:11058"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.1.4" test_ref="oval:org.mitre.oval:tst:10606"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ49024 are installed" test_ref="oval:org.mitre.oval:tst:10846"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10684"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.2.3" test_ref="oval:org.mitre.oval:tst:10664"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:631" version="2" class="vulnerability">
      <metadata>
        <title>up2date RPM GPG Signature Verification Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>up2date</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0546" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0546"/>
        <description>up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-03T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:48.365-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.112-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="up2date version is less than 3.1.23.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:2489"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rhnsd is running" negate="false" test_ref="oval:org.mitre.oval:tst:2488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6307" version="11" class="vulnerability">
      <metadata>
        <title>HP-UX Running XNTP, Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252"/>
        <description>Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:37.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:15.432-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:11.277-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:34.478-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:51.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:34:42.982-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:31.480-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:54.569-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:31.123-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10571 - March/April 2015 PFA Vulnerabilities for HP-UX security advisories" date="2015-04-28T15:04:00.685-04:00">
              <contributor organization="Hewlett-Packard">Jaikumar</contributor>
            </modified>
            <status_change date="2015-04-28T15:06:45.971-04:00">INTERIM</status_change>
            <status_change date="2015-05-18T04:00:14.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10552"/>
          <criterion negate="true" comment="Patch PHNE_39872 is installed" test_ref="oval:org.mitre.oval:tst:9736"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10571"/>
          <criterion negate="true" comment="Patch PHNE_39871 is installed" test_ref="oval:org.mitre.oval:tst:10557"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="NTP.NTP-RUN is installed" test_ref="oval:org.mitre.oval:tst:10348"/>
          <criterion negate="true" comment="Patch PHNE_39873 is installed" test_ref="oval:org.mitre.oval:tst:10276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6303" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overflow in autoconf6.</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5387"/>
        <description>Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-02T14:02:44-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-06T10:44:06.771-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:08.925-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:09.374-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6303 - Switched definition reference from one with an incorrect description to redundant definition with a correct description." date="2012-02-28T14:10:00.170-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-28T14:13:53.355-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:17.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IBM AIX 5300-00 through 5300-05 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-00 through 5300-05 is installed" definition_ref="oval:org.mitre.oval:def:6123"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-06 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:4813"/>
          <criterion negate="true" comment="All filesets for APAR IZ32172 are installed" test_ref="oval:org.mitre.oval:tst:10259"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ32051 are installed" test_ref="oval:org.mitre.oval:tst:9861"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ32016 are installed" test_ref="oval:org.mitre.oval:tst:10527"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ30238 are installed" test_ref="oval:org.mitre.oval:tst:10466"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ34753 are installed" test_ref="oval:org.mitre.oval:tst:10410"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ34393 are installed" test_ref="oval:org.mitre.oval:tst:10180"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ30231 are installed" test_ref="oval:org.mitre.oval:tst:10011"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6301" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846"/>
        <description>The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:14.263-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:10.825-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.772-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:35.489-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:51.511-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:34:47.234-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:31.275-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:56.067-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:30.942-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9858"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10546"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9864"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10283"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10041"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10495"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10331"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10556"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10551"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10305"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10501"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10039"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10539"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10262"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6276" version="1" class="vulnerability">
      <metadata>
        <title>Malloc subsystem in libc in IBM AIX 5.3 and 6.1 vulnerability.</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1786"/>
        <description>The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-18T15:10:44.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-20T22:24:02.312-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:07.163-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:09.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IBM AIX 5300-00 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-00 is installed" definition_ref="oval:org.mitre.oval:def:6195"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:9865"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 5.3.0.71" test_ref="oval:org.mitre.oval:tst:10347"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:10232"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 5.3.0.71" test_ref="oval:org.mitre.oval:tst:10072"/>
          <criterion negate="true" comment="All filesets for APAR IZ50500 are installed" test_ref="oval:org.mitre.oval:tst:10208"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-01 through 5300-06 always meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-01 through 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:5973"/>
          <criterion comment="Fileset bos.rte.libc is installed" test_ref="oval:org.mitre.oval:tst:10148"/>
          <criterion comment="Fileset bos.adt.prof is installed" test_ref="oval:org.mitre.oval:tst:9915"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10091"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 5.3.7.8" test_ref="oval:org.mitre.oval:tst:9830"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10412"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 5.3.7.8" test_ref="oval:org.mitre.oval:tst:10386"/>
          <criterion negate="true" comment="All filesets for APAR IZ50517 are installed" test_ref="oval:org.mitre.oval:tst:10103"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10088"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 5.3.8.5" test_ref="oval:org.mitre.oval:tst:10404"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10108"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 5.3.8.5" test_ref="oval:org.mitre.oval:tst:9768"/>
          <criterion negate="true" comment="All filesets for APAR IZ50447 are installed" test_ref="oval:org.mitre.oval:tst:10205"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:9956"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:9470"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:10233"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:10394"/>
          <criterion negate="true" comment="All filesets for APAR IZ50445 are installed" test_ref="oval:org.mitre.oval:tst:10321"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:10156"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 6.1.0.9" test_ref="oval:org.mitre.oval:tst:9908"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:10298"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 6.1.0.9" test_ref="oval:org.mitre.oval:tst:10426"/>
          <criterion negate="true" comment="All filesets for APAR IZ50139 are installed" test_ref="oval:org.mitre.oval:tst:10384"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:9918"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 6.1.1.4" test_ref="oval:org.mitre.oval:tst:9935"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:9872"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 6.1.1.4" test_ref="oval:org.mitre.oval:tst:10117"/>
          <criterion negate="true" comment="All filesets for APAR IZ50129 are installed" test_ref="oval:org.mitre.oval:tst:10403"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10419"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 6.1.2.3" test_ref="oval:org.mitre.oval:tst:10335"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10105"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 6.1.2.3" test_ref="oval:org.mitre.oval:tst:10322"/>
          <criterion negate="true" comment="All filesets for APAR IZ50121 are installed" test_ref="oval:org.mitre.oval:tst:10343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6256" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 9 fstat(2) System Call May Lead to a System Panic, Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1673"/>
        <description>The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argument of AT_FDCWD.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-20T10:58:53.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-05-27T17:29:30.743-04:00">DRAFT</status_change>
            <status_change date="2009-06-15T04:01:13.061-04:00">INTERIM</status_change>
            <status_change date="2009-07-06T04:00:49.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 257988">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-40 or later installed" test_ref="oval:org.mitre.oval:tst:9907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 257988">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-40 or later installed" test_ref="oval:org.mitre.oval:tst:10040"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6252" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in PostgreSQL Shipped with Solaris may Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0922" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0922"/>
        <description>PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T11:46:34.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-07-30T17:45:07.723-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:03.670-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:13.826-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 123590-10 or later installed" test_ref="oval:org.mitre.oval:tst:10235"/>
            <criterion comment="SUNWpostgr is installed" test_ref="oval:org.mitre.oval:tst:10073"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 136998-06 or later installed" test_ref="oval:org.mitre.oval:tst:10133"/>
            <criterion comment="SUNWpostgr-82* is installed" test_ref="oval:org.mitre.oval:tst:10339"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 138826-04 or later installed" test_ref="oval:org.mitre.oval:tst:10362"/>
            <criterion comment="SUNWpostgr-83* is installed" test_ref="oval:org.mitre.oval:tst:10361"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 123591-10 or later installed" test_ref="oval:org.mitre.oval:tst:10129"/>
            <criterion comment="SUNWpostgr is installed" test_ref="oval:org.mitre.oval:tst:10073"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 136999-06 or later installed" test_ref="oval:org.mitre.oval:tst:10164"/>
            <criterion comment="SUNWpostgr-82* is installed" test_ref="oval:org.mitre.oval:tst:10339"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 138827-04 or later installed" test_ref="oval:org.mitre.oval:tst:10385"/>
            <criterion comment="SUNWpostgr-83* is installed" test_ref="oval:org.mitre.oval:tst:10361"/>
          </criteria>
        </criteria>
        <criterion comment="Patch 136999-06 or later installed" test_ref="oval:org.mitre.oval:tst:10409"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6234" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the libxml2 Library Routines xmlBufferResize() May Lead to Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4225"/>
        <description>Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-13T15:56:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:31.147-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:28.318-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:21.781-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240546">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114014-22 or later installed" test_ref="oval:org.mitre.oval:tst:9654"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240546">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125731-04 or later installed" test_ref="oval:org.mitre.oval:tst:8710"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240546">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114015-22 or later installed" test_ref="oval:org.mitre.oval:tst:9487"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240546">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125732-04 or later installed" test_ref="oval:org.mitre.oval:tst:9600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:623" version="1" class="vulnerability">
      <metadata>
        <title>sysreport Plaintext Password Leak</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>sysreport</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1760"/>
        <description>sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="sysreport RPM earlier than 0:1.3.7.2-6" negate="false" test_ref="oval:org.mitre.oval:tst:2494"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/tmp is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:2493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6225" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris Print Service (in.lpd(1M)) May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2972" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2972"/>
        <description>in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-28T12:11:40.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-28T20:32:58.712-04:00">DRAFT</status_change>
            <status_change date="2009-09-14T04:00:08.792-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:05.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 264608">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109320-23 or later installed" test_ref="oval:org.mitre.oval:tst:10451"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 264608">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113329-07 or later installed" test_ref="oval:org.mitre.oval:tst:10764"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 264608">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109321-23 or later installed" test_ref="oval:org.mitre.oval:tst:10134"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 264608">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114980-09 or later installed" test_ref="oval:org.mitre.oval:tst:10602"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:622" version="6" class="vulnerability">
      <metadata>
        <title>Solaris 8, 9, 10 Blind Connection Reset Attack Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.491-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.160-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:46:00.662-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:47:31.744-05:00">INTERIM</status_change>
            <modified comment="Standardized title." date="2007-02-26T01:01:00.306-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:22.881-04:00">ACCEPTED</status_change>
            <modified comment="Added missing patch checks." date="2007-06-26T10:59:00.754-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </modified>
            <status_change date="2007-06-26T11:00:29.787-04:00">INTERIM</status_change>
            <status_change date="2007-07-11T15:17:33.358-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:622 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:42.080-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:38.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 116965-19 or later installed" test_ref="oval:org.mitre.oval:tst:4028"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 116966-18 or later installed" test_ref="oval:org.mitre.oval:tst:4069"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 118305-08 or later installed" test_ref="oval:org.mitre.oval:tst:3204"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 117470-07 or later installed" test_ref="oval:org.mitre.oval:tst:4114"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 118822-27 or later installed" test_ref="oval:org.mitre.oval:tst:3505"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 118844-28 or later installed" test_ref="oval:org.mitre.oval:tst:3302"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6219" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the libxml2 Library Routines xmlSAX2Characters() May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4226"/>
        <description>Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-13T15:56:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:31.658-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:27.722-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:21.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240546">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114014-22 or later installed" test_ref="oval:org.mitre.oval:tst:9654"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240546">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125731-04 or later installed" test_ref="oval:org.mitre.oval:tst:8710"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240546">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114015-22 or later installed" test_ref="oval:org.mitre.oval:tst:9487"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240546">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125732-04 or later installed" test_ref="oval:org.mitre.oval:tst:9600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6215" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX ttrace(2), Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1427"/>
        <description>Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown vectors related to the ttrace system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:13.063-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:09.428-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.529-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:44.718-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:31.152-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:26.481-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:30.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02450">
        <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:10434"/>
          <criterion comment="ProgSupport.PAUX-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:10443"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:10534"/>
        </criteria>
        <criterion negate="true" comment="Patch PHKL_40197 is installed" test_ref="oval:org.mitre.oval:tst:10541"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6203" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris keysock Kernel Module may Lead to a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0913" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0913"/>
        <description>Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv_01 through snv_108 allows local users to cause a denial of service (system panic) via unknown vectors related to PF_KEY socket, probably related to setting socket options.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-02T11:13:52.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-04-08T14:20:04.712-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:16.486-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:27.304-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 253568">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141008-01 or later installed" test_ref="oval:org.mitre.oval:tst:9765"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 253568">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141009-01 or later installed" test_ref="oval:org.mitre.oval:tst:9425"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:62" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 mibiisa Remote Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>mibiisa</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0797"/>
        <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File mibiisa exists" negate="false" test_ref="oval:org.mitre.oval:tst:2995"/>
          <criterion comment="Patch 107709-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mibiisa running" negate="false" test_ref="oval:org.mitre.oval:tst:2993"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6198" version="1" class="vulnerability">
      <metadata>
        <title>WPAR system call implementation in the kernel in IBM AIX 6.1 denial of service.</title>
        <affected family="unix">
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1597"/>
        <description>The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-08T13:29:53-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-12T18:17:13.139-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:09.166-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.272-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2008-1597">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ11571 are installed" test_ref="oval:org.mitre.oval:tst:10334"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2008-1597">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ09280 are installed" test_ref="oval:org.mitre.oval:tst:10173"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2008-1597">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ13392 are installed" test_ref="oval:org.mitre.oval:tst:10396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:619" version="2" class="vulnerability">
      <metadata>
        <title>UnZip 5.0 Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>unzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0282"/>
        <description>Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:46.657-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.784-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="unzip version is less than 5.50-33" negate="false" test_ref="oval:org.mitre.oval:tst:2498"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/unzip is executable">
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2497"/>
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2496"/>
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2495"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6183" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris dircmp(1) Shell Script may Allow Overwriting of Arbitrary Files</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1207"/>
        <description>Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-02T11:13:52.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-04-08T14:20:08.844-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:15.946-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:26.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 253468">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 140837-01 or later installed" test_ref="oval:org.mitre.oval:tst:9742"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 253468">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 138896-01 or later installed" test_ref="oval:org.mitre.oval:tst:9760"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 253468">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141014-01 or later installed" test_ref="oval:org.mitre.oval:tst:9632"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 253468">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 140838-01 or later installed" test_ref="oval:org.mitre.oval:tst:9652"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 253468">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 138897-01 or later installed" test_ref="oval:org.mitre.oval:tst:9731"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 253468">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141015-01 or later installed" test_ref="oval:org.mitre.oval:tst:9537"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6175" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Solaris lpadmin(1M) and ppdmgr(1M) Utilities May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0167" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0167"/>
        <description>Unspecified vulnerability in lpadmin in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to enumeration of "wrong printers," aka a "Temporary file vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-05T13:18:38.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-06T15:58:48.744-05:00">DRAFT</status_change>
            <status_change date="2009-02-23T04:00:23.607-05:00">INTERIM</status_change>
            <status_change date="2009-03-16T04:00:20.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249306">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 127127-11 installed" test_ref="oval:org.mitre.oval:tst:9551"/>
          <criterion negate="true" comment="Patch 139390-01 or later installed" test_ref="oval:org.mitre.oval:tst:9591"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249306">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 127128-11 installed" test_ref="oval:org.mitre.oval:tst:9422"/>
          <criterion negate="true" comment="Patch 139391-01 or later installed" test_ref="oval:org.mitre.oval:tst:8934"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6174" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Kerberos Incremental Propagation May Lead to a Denial of Service (DoS) Against Slave KDC Systems</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0923" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0923"/>
        <description>Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-02T11:13:52.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-04-08T14:20:10.595-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:15.389-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:26.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249926">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 138371-05 or later installed" test_ref="oval:org.mitre.oval:tst:9662"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249926">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 138372-05 or later installed" test_ref="oval:org.mitre.oval:tst:9253"/>
          </criteria>
        </criteria>
        <criterion comment="System is configured as a slave KDC" test_ref="oval:org.mitre.oval:tst:9764"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6168" version="1" class="vulnerability">
      <metadata>
        <title>Race Condition Security Vulnerability in Solaris Auditing Related to Extended File Attributes May Allow Local Unprivileged Users to Panic the System</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2644" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2644"/>
        <description>Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to "pathnames for invalid fds."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-10T16:40:08.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:49:57.004-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:08.660-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:05.908-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 264429">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 122300-42 or later installed" test_ref="oval:org.mitre.oval:tst:10143"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 264429">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 140921-02 or later installed" test_ref="oval:org.mitre.oval:tst:10518"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 264429">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 122301-42 or later installed" test_ref="oval:org.mitre.oval:tst:10507"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 264429">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 140922-02 or later installed" test_ref="oval:org.mitre.oval:tst:9991"/>
          </criteria>
        </criteria>
        <criterion comment="Solaris Auditing is enabled" test_ref="oval:org.mitre.oval:tst:10368"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:616" version="5" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 swagentd Denial of Service</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>swagentd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1389"/>
        <description>Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.134-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.789-04:00">ACCEPTED</status_change>
            <modified comment="Added title and CVE reference." date="2007-02-23T16:06:00.705-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T16:06:46.731-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.697-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.876-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.891-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-05T13:32:30.120-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:51.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Installed B.11.11 software has not been patched for c00622788" negate="false">
          <criteria operator="AND" comment="DCE-Core.DCE-CORE-SHLIB is installed without PHSS_29964 or subsequent" negate="false">
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3858"/>
            <criterion comment="Patch PHSS_29964 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3974"/>
          </criteria>
          <criteria operator="AND" comment="SW-DIST.SD-AGENT is installed without PHCO_28848 or subsequent" negate="false">
            <criterion comment="SW-DIST.SD-AGENT is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3857"/>
            <criterion comment="Patch PHCO_28848 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3831"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6155" version="1" class="vulnerability">
      <metadata>
        <title>at allows local users to read arbitrary files.</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0536" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0536"/>
        <description>at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-01T16:42:25-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-04T10:38:30.325-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:08.002-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:07.840-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 5200-10 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5200-10 is installed" definition_ref="oval:org.mitre.oval:def:5076"/>
          <criterion negate="true" comment="All filesets for APAR IZ43452 are installed" test_ref="oval:org.mitre.oval:tst:10346"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 5.2.0.0" test_ref="oval:org.mitre.oval:tst:10266"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 5.2.0.106" test_ref="oval:org.mitre.oval:tst:10308"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-00 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-00 is installed" definition_ref="oval:org.mitre.oval:def:6195"/>
          <criterion negate="true" comment="All filesets for APAR IZ43453 are installed" test_ref="oval:org.mitre.oval:tst:9585"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:10468"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 5.3.0.63" test_ref="oval:org.mitre.oval:tst:9900"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-01 through 5300-06 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-01 through 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:5973"/>
          <criterion comment="Fileset bos.rte.cron is installed" test_ref="oval:org.mitre.oval:tst:10547"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ43454 are installed" test_ref="oval:org.mitre.oval:tst:9728"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10447"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 5.3.7.1" test_ref="oval:org.mitre.oval:tst:10301"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ43455 are installed" test_ref="oval:org.mitre.oval:tst:10513"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10222"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 5.3.8.1" test_ref="oval:org.mitre.oval:tst:10374"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ43456 are installed" test_ref="oval:org.mitre.oval:tst:9949"/>
          <criterion comment="Fileset bos.rte.cron is equal to 5.3.9.0" test_ref="oval:org.mitre.oval:tst:10185"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ43457 are installed" test_ref="oval:org.mitre.oval:tst:9561"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:10376"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 6.1.0.1" test_ref="oval:org.mitre.oval:tst:10315"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ43458 are installed" test_ref="oval:org.mitre.oval:tst:9866"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:10517"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 6.1.1.2" test_ref="oval:org.mitre.oval:tst:9829"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ43459 are installed" test_ref="oval:org.mitre.oval:tst:10436"/>
          <criterion comment="Fileset bos.rte.cron is equal to 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6152" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris Kernel Involving the Interaction of the Filesystem and Virtual Memory Subsystems</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2857"/>
        <description>The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-21T11:07:35.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-21T20:56:31.695-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:11.548-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:15.555-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 257848">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 127721-02 or later installed" test_ref="oval:org.mitre.oval:tst:10639"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 257848">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-41 or later installed" test_ref="oval:org.mitre.oval:tst:10603"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 257848">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139555-08 or later installed" test_ref="oval:org.mitre.oval:tst:9767"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 257848">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 127722-02 or later installed" test_ref="oval:org.mitre.oval:tst:10324"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 257848">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-41 or later installed" test_ref="oval:org.mitre.oval:tst:10053"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 257848">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139556-08 or later installed" test_ref="oval:org.mitre.oval:tst:10254"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:615" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.969-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.625-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:52:00.850-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:52:49.873-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.517-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-05T13:32:30.580-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:51.288-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3641"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:614" version="2" class="vulnerability">
      <metadata>
        <title>SqirrelMail Cross-site Scripting Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>SquirrelMail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0160"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.275-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.549-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="squirrelmail version is less than 1.2.11-1" negate="false" test_ref="oval:org.mitre.oval:tst:2499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6136" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Simple Authentication and Security Layer (SASL) Library Bundled with the Java Enterprise System (JES) may Allow Unprivileged Users to Crash Applications Using the sasl_encode64 Function</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0688"/>
        <description>Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T11:14:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-07-30T17:45:06.789-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:03.181-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:11.189-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 264248">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 115328-08 or later installed" test_ref="oval:org.mitre.oval:tst:10445"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 264248">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 115342-08 or later installed" test_ref="oval:org.mitre.oval:tst:10367"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 264248">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 119345-07 or later installed" test_ref="oval:org.mitre.oval:tst:10193"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 264248">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 115343-08 or later installed" test_ref="oval:org.mitre.oval:tst:10455"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 264248">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 119346-07 or later installed" test_ref="oval:org.mitre.oval:tst:9898"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWsasl is installed" test_ref="oval:org.mitre.oval:tst:9482"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6118" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3283"/>
        <description>Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:14.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:48.650-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:53.320-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:33.216-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:12.168-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:51.165-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:46.646-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:31.007-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:27.171-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:30.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6116" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability with IKE Packet Handling in Solaris libike Library may Lead to a Crash of in.iked(1M)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0267"/>
        <description>libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T11:08:21.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:31.359-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:26.978-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:11.155-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 247406">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 113451-15 or later installed" test_ref="oval:org.mitre.oval:tst:9566"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 247406">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 140196-01 or later installed" test_ref="oval:org.mitre.oval:tst:8940"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 247406">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114435-14 or later installed" test_ref="oval:org.mitre.oval:tst:9611"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 247406">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 140414-01 or later installed" test_ref="oval:org.mitre.oval:tst:8709"/>
          </criteria>
        </criteria>
        <criterion comment="File /etc/inet/ike/config exists" test_ref="oval:org.mitre.oval:tst:9478"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6115" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java JRE and JDK, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5236" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5236"/>
        <description>Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:23.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:51.754-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:43.086-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:11.357-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:11.796-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:50.973-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:44.998-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:30.736-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:26.659-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:30.400-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02284">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9416"/>
            <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9358"/>
            <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9394"/>
            <criterion comment="Jre15.JRE15-COM-DOC version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9414"/>
            <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8712"/>
            <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9270"/>
            <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8441"/>
            <criterion comment="Jdk15.JDK15-DEMO version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8831"/>
            <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8698"/>
            <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9265"/>
            <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9276"/>
            <criterion comment="Jre15.JRE15-PNV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9409"/>
            <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9220"/>
            <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9132"/>
            <criterion comment="Jre15.JRE15-PNV2-H version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9244"/>
            <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8716"/>
            <criterion comment="Jre15.JRE15-PWV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9101"/>
            <criterion comment="Jre15.JRE15-PWV2-H version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9436"/>
            <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9097"/>
            <criterion comment="Jdk15.JDK15-PNV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9408"/>
            <criterion comment="Jdk15.JDK15-PWV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8733"/>
            <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02284">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Jdk14.JDK14-PWV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9417"/>
            <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9170"/>
            <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9382"/>
            <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9405"/>
            <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:8996"/>
            <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9007"/>
            <criterion comment="Jre14.JRE14-PNV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9402"/>
            <criterion comment="Jre14.JRE14-COM-DOC version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9437"/>
            <criterion comment="Jpi14.JPI14-COM version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:8465"/>
            <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9252"/>
            <criterion comment="Jre14.JRE14-PNV2-H version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9371"/>
            <criterion comment="Jre14.JRE14-PWV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9363"/>
            <criterion comment="Jpi14.JPI14-COM-DOC version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:8817"/>
            <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9400"/>
            <criterion comment="Jre14.JRE14-PWV2-H version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9420"/>
            <criterion comment="Jpi14.JPI14-IPF32 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9443"/>
            <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9390"/>
            <criterion comment="Jpi14.JPI14-PA11 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9028"/>
            <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9325"/>
            <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9274"/>
            <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9201"/>
            <criterion comment="Jdk14.JDK14-DEMO version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9334"/>
            <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9034"/>
            <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9284"/>
            <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9319"/>
            <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9455"/>
            <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9303"/>
            <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9464"/>
            <criterion comment="Jdk14.JDK14-PNV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9307"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6111" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1355"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:53.603-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:42.704-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:10.994-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:12.049-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:50.871-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:33:46.450-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:30.601-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:36:27.089-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:30.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criterion comment="hpuxwsAPACHE version is less than B.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9217"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsAPACHE version is less than A.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6105" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX running B6848AB GTK+ Support Libraries, Local Increased Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2693"/>
        <description>HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privileges via files in /opt/gnome/src/GLib/.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:54.163-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:42.423-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:10.352-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-05T13:32:12.647-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:50.755-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01034">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criterion comment="Gettext.GETTEXT-SRC version is less than 0.10.39.2.1" test_ref="oval:org.mitre.oval:tst:9045"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01034">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="GTK+.GTK+-SRC version is less than 1.2.10.2.1" test_ref="oval:org.mitre.oval:tst:9172"/>
            <criterion comment="GLib.GLIB-SRC version is less than 1.2.10.2.1" test_ref="oval:org.mitre.oval:tst:8999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6104" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running IPFilter, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0396"/>
        <description>Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T16:54:45.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:49.345-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:53.048-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:32.435-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:10.232-05:00">INTERIM</status_change>
            <status_change date="2014-03-10T04:00:51.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02181">
        <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        <criterion comment="IPF-HP.IPF-MIN is installed" test_ref="oval:org.mitre.oval:tst:8668"/>
        <criteria negate="true" operator="OR" comment="Patch PHNE_35545 and PHNE_35766 are installed">
          <criterion comment="Patch PHNE_35545 is installed" test_ref="oval:org.mitre.oval:tst:8875"/>
          <criterion comment="Patch PHNE_35766 is installed" test_ref="oval:org.mitre.oval:tst:9179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:610" version="5" class="vulnerability">
      <metadata>
        <title>HP-UX AutoRAID Critical Functionality Issue</title>
        <affected family="unix">
          <platform>HP-UX 10</platform>
          <product>AutoRAID Manager</product>
        </affected>
        <reference source="MISC" ref_id="PHCO_23261" ref_url="http://www.itrc.hp.com/service/cki/patchDocDisplay.do?patchId=PHCO_23261"/>
        <description>Possible unknown vulnerability or vulnerabilities in HP DiskArray Utilities with AutoRAID Manager.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.786-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.424-04:00">ACCEPTED</status_change>
            <modified comment="Added title and reference, updated description and product." date="2007-02-26T15:48:00.739-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-26T15:49:57.767-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.307-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.769-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.759-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:610 - Typo Corrections" date="2014-05-22T11:03:00.270-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:06:08.156-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:45.320-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.X">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.20">
            <criteria operator="AND" comment="700 Series OS Release 10.20">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.20" test_ref="oval:org.mitre.oval:tst:3807"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.20">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.20" test_ref="oval:org.mitre.oval:tst:3807"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.01">
            <criteria operator="AND" comment="700 Series OS Release 10.01">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.01" test_ref="oval:org.mitre.oval:tst:3581"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.01">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.01" test_ref="oval:org.mitre.oval:tst:3581"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.10">
            <criteria operator="AND" comment="700 Series OS Release 10.10">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.10" test_ref="oval:org.mitre.oval:tst:3985"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.10">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.10" test_ref="oval:org.mitre.oval:tst:3985"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.30">
            <criteria operator="AND" comment="700 Series OS Release 10.30">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.30" test_ref="oval:org.mitre.oval:tst:3461"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.30">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.30" test_ref="oval:org.mitre.oval:tst:3461"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.ADMN-ENG-A-MAN or OS-Core.C2400-UTIL is installed">
          <criterion comment="OS-Core.ADMN-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:3370"/>
          <criterion comment="OS-Core.C2400-UTIL is installed" test_ref="oval:org.mitre.oval:tst:3376"/>
        </criteria>
        <criterion negate="true" comment="Patch PHCO_23261 is installed" test_ref="oval:org.mitre.oval:tst:3674"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6094" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T11:23:00.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:30.107-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:59.363-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:01:00.185-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 241646">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 118192-02 or later installed" test_ref="oval:org.mitre.oval:tst:10043"/>
          <criterion comment="Patch 118192-01 or later installed" test_ref="oval:org.mitre.oval:tst:10160"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6092" version="3" class="vulnerability">
      <metadata>
        <title>Integer Overflow Vulnerability in the Solaris 8 and 9 sadmind(1M) Daemon May Lead to Arbitrary Code Execution</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3870"/>
        <description>Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request that triggers a heap-based buffer overflow, related to improper memory allocation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-28T13:34:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-06-05T14:12:44.849-04:00">DRAFT</status_change>
            <status_change date="2009-06-22T04:00:27.049-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:47.597-04:00">ACCEPTED</status_change>
            <modified comment="Fixed incorrect user_id element value in process_state.  Incorrect value was 'root', updated to value of '0'." date="2010-09-02T15:11:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T15:13:53.660-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:32.984-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 259468">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 116455-02 or later installed" test_ref="oval:org.mitre.oval:tst:9833"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 259468">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 116453-03 or later installed" test_ref="oval:org.mitre.oval:tst:9695"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 259468">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 116442-02 or later installed" test_ref="oval:org.mitre.oval:tst:10038"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 259468">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 116454-03 or later installed" test_ref="oval:org.mitre.oval:tst:10171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration Section">
          <criterion comment="inetd running" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criterion comment="inetd.conf contains sadmind" test_ref="oval:org.mitre.oval:tst:1023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6089" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Cross Site Scripting (XSS) or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4465"/>
        <description>Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset.  NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-28T13:04:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-28T14:12:21.198-04:00">DRAFT</status_change>
            <status_change date="2008-09-15T04:00:29.076-04:00">INTERIM</status_change>
            <status_change date="2008-10-06T04:00:20.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:05.736-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:50.601-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:28.574-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:30.477-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:39.402-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:30.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9113"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8969"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPCH32.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9088"/>
            <criterion comment="hpuxwsAPCH32.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9123"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8990"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9023"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8708"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9120"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8971"/>
            <criterion comment="hpuxwsAPCH32.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9208"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9146"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6088" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris ip(7P) Kernel Module's IP-in-IP Packet Processing May Lead to a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0346"/>
        <description>The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-05T13:18:38.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-06T15:58:53.969-05:00">DRAFT</status_change>
            <status_change date="2009-02-23T04:00:23.036-05:00">INTERIM</status_change>
            <status_change date="2009-03-16T04:00:16.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240086">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-38 or later installed" test_ref="oval:org.mitre.oval:tst:9675"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240086">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138888-03 or later installed" test_ref="oval:org.mitre.oval:tst:8820"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240086">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-26 or later installed" test_ref="oval:org.mitre.oval:tst:9614"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240086">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138889-03 or later installed" test_ref="oval:org.mitre.oval:tst:9254"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6085" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris SSH May Allow Unauthorized Access to X11 Sessions</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1483" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1483"/>
        <description>OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-25T11:33:40.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-08-28T14:12:27.939-04:00">DRAFT</status_change>
            <status_change date="2008-09-15T04:00:28.608-04:00">INTERIM</status_change>
            <status_change date="2008-10-06T04:00:20.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237444">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 114356-14 or later installed" test_ref="oval:org.mitre.oval:tst:9096"/>
            <criterion comment="X11Forwarding is enabled" test_ref="oval:org.mitre.oval:tst:9067"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237444">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114357-13 or later installed" test_ref="oval:org.mitre.oval:tst:9157"/>
            <criterion comment="X11Forwarding is enabled" test_ref="oval:org.mitre.oval:tst:9067"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237444">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 126133-03 or later installed" test_ref="oval:org.mitre.oval:tst:9197"/>
            <criterion negate="true" comment="X11Forwarding is not enabled" test_ref="oval:org.mitre.oval:tst:9165"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237444">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 126134-03 or later installed" test_ref="oval:org.mitre.oval:tst:9048"/>
            <criterion negate="true" comment="X11Forwarding is not enabled" test_ref="oval:org.mitre.oval:tst:9165"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="sshd running" test_ref="oval:org.mitre.oval:tst:484"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6084" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Cross Site Scripting (XSS) or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2364"/>
        <description>The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-28T13:04:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-28T14:12:28.294-04:00">DRAFT</status_change>
            <status_change date="2008-09-15T04:00:28.002-04:00">INTERIM</status_change>
            <status_change date="2008-10-06T04:00:19.705-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:08.476-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:50.306-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:34.405-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:30.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:43.033-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:29.943-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9113"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8969"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPCH32.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9088"/>
            <criterion comment="hpuxwsAPCH32.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9123"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8990"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9023"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8708"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9120"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8971"/>
            <criterion comment="hpuxwsAPCH32.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9208"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9146"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6078" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2930" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2930"/>
        <description>Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a single-threaded regular-expression subsystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:14.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:49.621-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:52.468-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:31.819-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:07.200-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:50.122-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:32.096-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:30.162-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:41.538-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:29.798-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6077" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4416"/>
        <description>Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-05T16:36:25.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:31.643-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:38.394-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:17.990-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:32.030-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:30.084-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:41.470-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:29.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02389">
        <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:9511"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9181"/>
        </criteria>
        <criterion negate="true" comment="Patch PHKL_38987 is installed" test_ref="oval:org.mitre.oval:tst:9485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6076" version="1" class="vulnerability">
      <metadata>
        <title>automountd can run user programs as root.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0210"/>
        <description>Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-31T10:44:28.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:54.422-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:41.254-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:09.037-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9910-104">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_20371 is installed" test_ref="oval:org.mitre.oval:tst:8490"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6067" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1900" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1900"/>
        <description>CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:54.701-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:40.429-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:07.722-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:04.083-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:50.026-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:23.919-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:29.995-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:36.830-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:29.559-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criterion comment="hpuxwsAPACHE version is less than B.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9217"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsAPACHE version is less than A.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6061" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris Pseudo-terminal Driver (pty(7D)) may Cause a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0268"/>
        <description>Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T11:08:21.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:32.895-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:26.165-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:10.700-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 249586">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 113685-07 or later installed" test_ref="oval:org.mitre.oval:tst:9513"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 249586">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 140426-01 or later installed" test_ref="oval:org.mitre.oval:tst:9267"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249586">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 140383-01 or later installed" test_ref="oval:org.mitre.oval:tst:9659"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 249586">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 113686-06 or later installed" test_ref="oval:org.mitre.oval:tst:9438"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 249586">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 140427-01 or later installed" test_ref="oval:org.mitre.oval:tst:9498"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249586">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 140384-01 or later installed" test_ref="oval:org.mitre.oval:tst:9523"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6056" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3378"/>
        <description>The (1) session_save_path, (2) ini_set, and (3) error_log functions in PHP 4.4.7 and earlier, and PHP 5 5.2.3 and earlier, when invoked from a .htaccess file, allow remote attackers to bypass safe_mode and open_basedir restrictions and possibly execute arbitrary commands, as demonstrated using (a) php_value, (b) php_flag, and (c) directives in .htaccess.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:23.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:55.053-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:40.167-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:07.424-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:14:04.800-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:49.929-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:25.842-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:29.901-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:37.825-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:29.451-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02308">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criterion comment="hpuxwsAPACHE version is less than B.2.0.59.00.2" test_ref="oval:org.mitre.oval:tst:9344"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02308">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsAPACHE version is less than A.2.0.59.00.2" test_ref="oval:org.mitre.oval:tst:9329"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6051" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the BIND executable</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0009"/>
        <description>Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-31T10:44:28.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:55.296-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:39.940-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:07.182-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9808-083">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_12957 is installed" test_ref="oval:org.mitre.oval:tst:9061"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6038" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris IP(7p) Implementation, Related to Minor Number Allocation, may Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0480" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0480"/>
        <description>The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-10T11:19:01.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:54.282-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:19.981-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:16.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 248026">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 116965-34 or later installed" test_ref="oval:org.mitre.oval:tst:9631"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 248026">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-37 or later installed" test_ref="oval:org.mitre.oval:tst:9582"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 248026">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138888-01 or later installed" test_ref="oval:org.mitre.oval:tst:9474"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 248026">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 116966-33 or later installed" test_ref="oval:org.mitre.oval:tst:9681"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 248026">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-25 or later installed" test_ref="oval:org.mitre.oval:tst:8868"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 248026">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138889-01 or later installed" test_ref="oval:org.mitre.oval:tst:9661"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6037" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX Running LDAP-UX, Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1659" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1659"/>
        <description>Unspecified vulnerability in HP LDAP-UX vB.04.10 through vB.04.15 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:55.970-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:39.593-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:06.661-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:51.738-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:49.832-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:35:45.035-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:29.793-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:18.079-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:29.313-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02330">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="LdapUxClient.ADMIN-RUN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9322"/>
          <criterion comment="LdapUxClient.CORE-RUN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9278"/>
          <criterion comment="LdapUxClient.LDAP-C-SDK version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9218"/>
          <criterion comment="LdapUxClient.LDUX-ENG-A-MAN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:8631"/>
          <criterion comment="LdapUxClient.NATIVELDAP-RUN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9384"/>
          <criterion comment="LdapUxClient.PAM-AUTHZ-RUN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9415"/>
          <criterion comment="NisLdapServer.YPLDAP-SERVER version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9114"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6033" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX Running Firefox, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6589" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6589"/>
        <description>The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:56.312-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:39.354-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:06.284-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:51.238-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:49.747-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02153">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        </criteria>
        <criterion comment="Firefox.FFOX-COM version is less than 2.0.0.11" test_ref="oval:org.mitre.oval:tst:9300"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:603" version="4" class="vulnerability">
      <metadata>
        <title>Sendmail BO in prescan Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694"/>
        <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.124-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.318-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.305-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:57:46.056-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:32.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-9.90" negate="false" test_ref="oval:org.mitre.oval:tst:2518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6028" version="1" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in IBM AIX rmsock."</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0370"/>
        <description>Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-07T08:18:16-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-10T08:38:33.830-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:07.513-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:05.256-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="IBM AIX 5200-10 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5200-10 is installed" definition_ref="oval:org.mitre.oval:def:5076"/>
            <criterion negate="true" comment="All filesets for APAR IZ40386 are installed" test_ref="oval:org.mitre.oval:tst:10435"/>
            <criterion comment="The level of fileset bos.net.tcp.client is greater than or equal 5.2.0.0" test_ref="oval:org.mitre.oval:tst:7050"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-00 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-00 is installed" definition_ref="oval:org.mitre.oval:def:6195"/>
            <criterion negate="true" comment="All filesets for APAR IZ42785 are installed" test_ref="oval:org.mitre.oval:tst:10381"/>
            <criterion comment="The level of fileset bos.net.tcp.client is less than or equal 5.3.0.72" test_ref="oval:org.mitre.oval:tst:10478"/>
            <criterion comment="The level of fileset bos.net.tcp.client is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:7735"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-01 through 5300-06 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-01 through 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:5973"/>
            <criterion comment="Fileset bos.net.tcp.client is installed" test_ref="oval:org.mitre.oval:tst:10479"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
            <criterion negate="true" comment="All filesets for APAR IZ42786 are installed" test_ref="oval:org.mitre.oval:tst:10467"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10553"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 5.3.7.7" test_ref="oval:org.mitre.oval:tst:10423"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
            <criterion negate="true" comment="All filesets for APAR IZ42787 are installed" test_ref="oval:org.mitre.oval:tst:10458"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10190"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 5.3.8.6" test_ref="oval:org.mitre.oval:tst:10285"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
            <criterion negate="true" comment="All filesets for APAR IZ42788 are installed" test_ref="oval:org.mitre.oval:tst:9578"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:10444"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:10464"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
            <criterion negate="true" comment="All filesets for APAR IZ41599 are installed" test_ref="oval:org.mitre.oval:tst:9887"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:10562"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 6.1.0.7" test_ref="oval:org.mitre.oval:tst:10282"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
            <criterion negate="true" comment="All filesets for APAR IZ41593 are installed" test_ref="oval:org.mitre.oval:tst:10561"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:10514"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 6.1.1.3" test_ref="oval:org.mitre.oval:tst:10497"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
            <criterion negate="true" comment="All filesets for APAR IZ41510 are installed" test_ref="oval:org.mitre.oval:tst:9672"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10487"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 6.1.2.2" test_ref="oval:org.mitre.oval:tst:10528"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Configuration Section">
          <criterion comment="/usr/sbin/rmsock is suid" test_ref="oval:org.mitre.oval:tst:10496"/>
          <criterion comment="/usr/sbin/rmsock64 is suid" test_ref="oval:org.mitre.oval:tst:10491"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6195" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 5300-00 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:5.3"/>
        <description>The operating system installed on the system is IBM AIX version 5300-00.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-20T12:00:00.000-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-20T22:24:00.441-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:03.501-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:12.484-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Version of IBM AIX installed is 5300-00" test_ref="oval:org.mitre.oval:tst:10391"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5973" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 5300-01 through 5300-06 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:5.3"/>
        <description>The operating system installed on the system is IBM AIX version 5300-01 through 5300-06.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-20T12:00:00.000-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-20T22:24:00.911-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:02.775-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:10.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IBM AIX version is greater than or equal 5300-01" test_ref="oval:org.mitre.oval:tst:9727"/>
        <criterion comment="IBM AIX version is less than or equal 5300-06" test_ref="oval:org.mitre.oval:tst:10071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6022" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX running CDE, Local Increased Privilege, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0772"/>
        <description>Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in HP-UX 10.10 through 11.11 allow attackers to cause a denial of service and possibly gain additional privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T16:54:45.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:51.351-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:51.956-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:31.150-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-05T13:32:46.913-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:49.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE.CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:9060"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_24098 is installed" test_ref="oval:org.mitre.oval:tst:8626"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
          </criteria>
          <criteria negate="true" operator="OR" comment="Patch PHSS_24087 and PHSS_24091 are installed">
            <criterion comment="Patch PHSS_24087 is installed" test_ref="oval:org.mitre.oval:tst:9194"/>
            <criterion comment="Patch PHSS_24091 is installed" test_ref="oval:org.mitre.oval:tst:9148"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8916"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_23797 is installed" test_ref="oval:org.mitre.oval:tst:9212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6009" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the Virtual Host Manager in Tomcat 5.5 bundled with Solaris 9 and Solaris 10 may lead to Cross Site Scripting (XSS).</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1947"/>
        <description>Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-26T10:58:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-27T16:20:22.124-05:00">DRAFT</status_change>
            <status_change date="2009-03-16T04:00:16.528-04:00">INTERIM</status_change>
            <status_change date="2009-04-06T04:00:18.038-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software Section">
        <criteria operator="OR">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 114016-03 or later installed" test_ref="oval:org.mitre.oval:tst:9634"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 122911-15 or later installed" test_ref="oval:org.mitre.oval:tst:9605"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114017-03 or later installed" test_ref="oval:org.mitre.oval:tst:9480"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 122912-15 or later installed" test_ref="oval:org.mitre.oval:tst:9406"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWtcatr is installed" test_ref="oval:org.mitre.oval:tst:9550"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6003" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the X Inter Client Exchange Library (libICE) Shipped With Solaris May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5684" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5684"/>
        <description>Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv_85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-05T16:39:26.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-01-09T14:23:46.445-05:00">DRAFT</status_change>
            <status_change date="2009-01-26T04:00:20.280-05:00">INTERIM</status_change>
            <status_change date="2009-02-16T04:00:24.753-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 243566">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 119067-11 or later installed" test_ref="oval:org.mitre.oval:tst:9572"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 243566">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112785-65 or later installed" test_ref="oval:org.mitre.oval:tst:9617"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 243566">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119059-46 or later installed" test_ref="oval:org.mitre.oval:tst:9472"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 243566">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 119068-11 or later installed" test_ref="oval:org.mitre.oval:tst:9453"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 243566">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 112786-54 or later installed" test_ref="oval:org.mitre.oval:tst:9118"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 243566">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119060-45 or later installed" test_ref="oval:org.mitre.oval:tst:9264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6002" version="9" class="vulnerability">
      <metadata>
        <title>HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1860" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1860"/>
        <description>mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:56.476-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:39.071-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:05.253-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:57.737-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:49.526-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - PFA Vulnerability Definitions for February HP-UX security advisory" date="2015-03-06T12:24:00.373-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2015-03-06T12:36:02.190-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:29.705-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8260 - Fixed erroneous modification made to tst:8260 on 3/6/2015" date="2015-03-31T13:26:00.992-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-03-31T13:37:25.993-04:00">INTERIM</status_change>
            <status_change date="2015-04-20T04:02:29.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criterion comment="hpuxwsAPACHE version is less than B.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9217"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsAPACHE version is less than A.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:60" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8 AdminTool Media Installation Path Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0088"/>
        <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:23:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:32.137-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1726, which had been badly mangled during conversion from OVAL 4.2 to 5.0.  Operation set to pattern match on path, and terminal regexp anchor moved from filename to path." date="2007-01-22T16:24:00.728-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:26:01.046-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:48.356-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6" version="4" class="vulnerability">
      <metadata>
        <title>Common Unix Printing System Partial Print DOS</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Common Unix Printing System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0195"/>
        <description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:56.350-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.018-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.024-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:55:16.846-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:32.153-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cups version is less than 1.1.17-13.3" negate="false" test_ref="oval:org.mitre.oval:tst:3147"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="cupsd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:3146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5993" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T11:23:00.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:32.738-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:52.639-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:54.861-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 241646">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 118191-02 or later installed" test_ref="oval:org.mitre.oval:tst:9793"/>
          <criterion comment="Patch 118191-01 or later installed" test_ref="oval:org.mitre.oval:tst:9763"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5988" version="3" class="vulnerability">
      <metadata>
        <title>tftp buffer overflow allows local users to gain privileges</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6717" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6717"/>
        <description>Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-12T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-12T12:50:00.316-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:50.400-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:29.530-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5988 - Typo Corrections" date="2014-05-22T11:01:00.943-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:03:39.904-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:44.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IBM AIX 5200-10 meets CVE-2007-6717">
          <extend_definition comment="IBM AIX 5200-10 is installed" definition_ref="oval:org.mitre.oval:def:5076"/>
          <criterion negate="true" comment="All filesets for APAR IZ03054 are installed" test_ref="oval:org.mitre.oval:tst:9024"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-06 meets CVE-2007-6717">
          <extend_definition comment="IBM AIX 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:4813"/>
          <criterion negate="true" comment="All filesets for APAR IZ03060 are installed" test_ref="oval:org.mitre.oval:tst:9345"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2007-6717">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ03392 are installed" test_ref="oval:org.mitre.oval:tst:8827"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5985" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the HttpServletResponse.sendError method in Tomcat 5.5 bundled with Solaris 9 and Solaris 10 may lead to Cross Site Scripting (XSS).</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1232"/>
        <description>Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-26T10:58:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-27T16:20:22.464-05:00">DRAFT</status_change>
            <status_change date="2009-03-16T04:00:16.102-04:00">INTERIM</status_change>
            <status_change date="2009-04-06T04:00:17.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software Section">
        <criteria operator="OR">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 114016-03 or later installed" test_ref="oval:org.mitre.oval:tst:9634"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 122911-15 or later installed" test_ref="oval:org.mitre.oval:tst:9605"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114017-03 or later installed" test_ref="oval:org.mitre.oval:tst:9480"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 122912-15 or later installed" test_ref="oval:org.mitre.oval:tst:9406"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWtcatr is installed" test_ref="oval:org.mitre.oval:tst:9550"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:598" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX Running xterm Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3779"/>
        <description>Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.676-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.645-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02075" date="2008-07-14T10:21:00.902-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:23:55.918-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.071-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:36.379-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:49.414-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34102 is installed" test_ref="oval:org.mitre.oval:tst:8317"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34160 is installed" test_ref="oval:org.mitre.oval:tst:8362"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34159 is installed" test_ref="oval:org.mitre.oval:tst:8389"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5978" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T11:23:00.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:33.789-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:51.856-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:53.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 241646">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139099-01 or later installed" test_ref="oval:org.mitre.oval:tst:9629"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5977" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris "autofs" Kernel Module may Allow a Local Unprivileged User to Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0319"/>
        <description>Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-05T13:18:38.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-06T15:58:55.814-05:00">DRAFT</status_change>
            <status_change date="2009-02-23T04:00:21.897-05:00">INTERIM</status_change>
            <status_change date="2009-03-16T04:00:15.050-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 249966">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 128624-09 or later installed" test_ref="oval:org.mitre.oval:tst:9674"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 249966">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 113318-34 or later installed" test_ref="oval:org.mitre.oval:tst:9559"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249966">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 139560-01 or later installed" test_ref="oval:org.mitre.oval:tst:9658"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 249966">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 128625-09 or later installed" test_ref="oval:org.mitre.oval:tst:9544"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 249966">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 116053-03 or later installed" test_ref="oval:org.mitre.oval:tst:9593"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249966">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 139561-01 or later installed" test_ref="oval:org.mitre.oval:tst:8913"/>
          </criteria>
        </criteria>
        <criterion comment="autofs is enabled" test_ref="oval:org.mitre.oval:tst:9385"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5971" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running ftpd, Remote Privileged Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1668" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1668"/>
        <description>ftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which PAM authentication can succeed even though no passwd entry is available for a user, which allows remote attackers to gain privileges, as demonstrated by a login attempt for an LDAP account when nsswitch.conf does not specify LDAP for passwd information.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-12T16:30:32.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:35.905-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:19.712-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:38.867-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-05T13:32:32.486-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:49.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02356">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:9029"/>
        <criterion negate="true" comment="Patch PHNE_38458 is installed" test_ref="oval:org.mitre.oval:tst:9107"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:597" version="4" class="vulnerability">
      <metadata>
        <title>Denial of Service in Sendmail via the enhdnsbl Feature</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0688"/>
        <description>The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:49.069-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:36.804-04:00">ACCEPTED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.764-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T20:58:05.332-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:31.764-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-6.90" negate="false" test_ref="oval:org.mitre.oval:tst:2517"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sendmail is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2516"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5966" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the BIND executable</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0011" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0011"/>
        <description>Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-31T10:44:28.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:57.169-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:38.552-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:04.005-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9808-083">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_12957 is installed" test_ref="oval:org.mitre.oval:tst:9061"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5960" version="1" class="vulnerability">
      <metadata>
        <title>SUNRAS Plugin of Gimp Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2356"/>
        <description>Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-11T11:37:41.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:06.257-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:49.434-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:28.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 122212-22 or later installed" test_ref="oval:org.mitre.oval:tst:8701"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 121775-01 or later installed" test_ref="oval:org.mitre.oval:tst:9219"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 122213-22 or later installed" test_ref="oval:org.mitre.oval:tst:8353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:596" version="8" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 or 11.23 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.438-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.897-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:53:00.683-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:54:12.704-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:21.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:596 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:49.880-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:37.359-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3901 - HP-UX Security Advisory - HPSBUX02944_101" date="2014-02-19T09:09:00.021-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-02-19T09:13:37.611-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-24T04:01:49.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5958" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX running CDE, Local Increased Privilege, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0551"/>
        <description>Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T16:54:45.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:51.818-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:48.724-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:27.315-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3704 - HP-UX Security Advisories published in February 2014" date="2014-03-05T13:28:00.446-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </modified>
            <status_change date="2014-03-05T13:32:26.388-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:49.125-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE-TT is