<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T07:02:52.079-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:22420" version="3" class="vulnerability">
      <metadata>
        <title>The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-4353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4353"/>
        <description>The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-27T13:00:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-02-28T15:23:50.821-05:00">DRAFT</status_change>
            <status_change date="2014-03-17T04:00:18.401-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:02:47.119-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="OpenSSL 1.0.1 before 1.0.1f" test_ref="oval:org.mitre.oval:tst:100449"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <rpminfo_test id="oval:org.mitre.oval:tst:100449" version="1" comment="OpenSSL 1.0.1 before 1.0.1f" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30443"/>
      <state state_ref="oval:org.mitre.oval:ste:27720"/>
    </rpminfo_test>
  </tests>
  <objects>
    <rpminfo_object id="oval:org.mitre.oval:obj:30443" version="1" comment="the rpm package openssl" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl</name>
    </rpminfo_object>
  </objects>
  <states>
    <rpminfo_state id="oval:org.mitre.oval:ste:27720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">1.0.1[a-e].*</version>
    </rpminfo_state>
  </states>
</oval_definitions>